Extension WordPress

Vulnérabilités Database for Contact Form 7, WPforms, Elementor forms

Cette page rassemble les failles publiées pour Database for Contact Form 7, WPforms, Elementor forms, leurs plages de versions affectées et les correctifs signalés dans la base locale.

17Vulnérabilités
2Critiques
17Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Database for Contact Form 7, WPforms, Elementor forms

17 fiches

CVE-2026-57708 Élevée · 7,2
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 – Unauthenticated Stored Cross-Site Scripting

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.5.2

Correctif

1.5.3

Publication

10/07/2026

CVE-2026-9145 Moyenne · 6,5
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 – Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object…

Versions affectées

*-1.5.1

Correctif

1.5.2

Publication

01/07/2026

CVE-2026-9843 Élevée · 8,1
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 – Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes…

Versions affectées

*-1.5.1

Correctif

1.5.2

Publication

19/06/2026

CVE-2026-3831 Moyenne · 4,3
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 – Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This…

Versions affectées

*-1.4.9

Correctif

1.5.0

Publication

31/03/2026

CVE-2026-2599 Critique · 9,8
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 – Unauthenticated PHP Object Injection via 'download_csv'

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it…

Versions affectées

*-1.4.7

Correctif

1.4.8

Publication

04/03/2026

CVE-2026-0825 Moyenne · 5,3
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 – Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it…

Versions affectées

*-1.4.5

Correctif

1.4.6

Publication

27/01/2026

CVE-2025-7384 Critique · 9,8
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 – Unauthenticated PHP Object Injection to Arbitrary File Deletion

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it…

Versions affectées

*-1.4.3

Correctif

1.4.4

Publication

12/08/2025

CVE-2024-3715 Élevée · 7,2
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 – Unauthenticated Stored Cross-Site Scripting

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-1.3.8

Correctif

1.3.9

Publication

22/04/2024

CVE-2024-2030 Moyenne · 6,4
Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 – Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping…

Versions affectées

*-1.3.3

Correctif

1.3.4

Publication

06/03/2024

CVE-2024-1069 Élevée · 7,2
Database for Contact Form 7, WPforms, Elementor forms

Contact Form Entries <= 1.3.2 – Authenticated (Administrator+) Arbitrary File Upload

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level…

Versions affectées

*-1.3.2

Correctif

1.3.3

Publication

30/01/2024

CVE-2023-33311 Moyenne · 6,4
Database for Contact Form 7, WPforms, Elementor forms

Contact Form Entries <= 1.3.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via vx-entries shortcode

The Contact Form Entries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vx-entries' shortcode attributes in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

22/05/2023

CVE-2023-31212 Élevée · 8,8
Database for Contact Form 7, WPforms, Elementor forms

Contact Form Entries <= 1.3.0 – Authenticated (Contributor+) SQL Injection via shortcode

The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attributes in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

22/05/2023

Vulnérabilité Moyenne · 6,1
Database for Contact Form 7, WPforms, Elementor forms

CRM Perks – Various Plugins (Various Versions) – Reflected Cross-Site Scripting

Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.2.1

Correctif

1.2.2

Publication

26/08/2021

Vulnérabilité Moyenne · 6,1
Database for Contact Form 7, WPforms, Elementor forms

Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 – Reflected Cross-Site Scripting

The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization…

Versions affectées

*-1.2.0

Correctif

1.2.1

Publication

24/08/2021

CVE-2021-25080 Élevée · 7,2
Database for Contact Form 7, WPforms, Elementor forms

Contact Form Entries <= 1.1.6 – Unauthenticated Stored Cross-Site Scripting

The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing…

Versions affectées

*-1.1.6

Correctif

1.1.7

Publication

05/01/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités