Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Mar 31, 2026

Database for Contact Form 7, WPforms, Elementor forms Vulnerabilities

Review known vulnerability records for the WordPress plugin Database for Contact Form 7, WPforms, Elementor forms (`contact-form-entries`), including severity, CVE references, affected versions, and patch status.

Known Records
13
High or Critical
7
Linked CVEs
12
Last Updated
Mar 31, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Database for Contact Form 7, WPforms, Elementor forms so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
13 records include a published patch path.
Severity Mix
2 critical and 5 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Database for Contact Form 7, WPforms, Elementor forms

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-3831
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated...

Published
Mar 31, 2026
Patched Release
1.5.0
Affected Versions
Versions up to 1.4.9
Next Step
Update to 1.5.0 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-2599
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attac...

Published
Mar 04, 2026
Patched Release
1.4.8
Affected Versions
Versions up to 1.4.7
Next Step
Update to 1.4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0825
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers...

Published
Jan 27, 2026
Patched Release
1.4.6
Affected Versions
Versions up to 1.4.5
Next Step
Update to 1.4.6 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-7384
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated atta...

Published
Aug 12, 2025
Patched Release
1.4.4
Affected Versions
Versions up to 1.4.3
Next Step
Update to 1.4.4 or newer if supported.
Plugin High Patched: Yes CVE-2024-3715
Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

Published
Apr 22, 2024
Patched Release
1.3.9
Affected Versions
Versions up to 1.3.8
Next Step
Update to 1.3.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2030
Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attrib...

Published
Mar 06, 2024
Patched Release
1.3.4
Affected Versions
Versions up to 1.3.3
Next Step
Update to 1.3.4 or newer if supported.
Plugin High Patched: Yes CVE-2024-1069
Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities...

Published
Jan 30, 2024
Patched Release
1.3.3
Affected Versions
Versions up to 1.3.2
Next Step
Update to 1.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-33311
Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via vx-entries shortcode

The Contact Form Entries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vx-entries' shortcode attributes in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

Published
May 22, 2023
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin High Patched: Yes CVE-2023-31212
Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via shortcode

The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attributes in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...

Published
May 22, 2023
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin High Patched: Yes CVE-2022-3604
Contact Form Entries <= 1.2.9 - CSV Injection

The Contact Form Entries plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.9 when outputting to a CSV file. This allows low-level attackers to embed untrusted input contact forms that will be present in exported CSV files, which can result...

Published
Oct 21, 2022
Patched Release
1.3.0
Affected Versions
Versions up to 1.2.9
Next Step
Update to 1.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-25079
Contact Form Entries <= 1.2.3 - Reflected Cross-Site Scripting

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

Published
Nov 14, 2021
Patched Release
1.2.4
Affected Versions
Versions up to 1.2.3
Next Step
Update to 1.2.4 or newer if supported.
Plugin Medium Patched: Yes
Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 - Reflected Cross-Site Scripting

The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This...

Published
Aug 24, 2021
Patched Release
1.2.1
Affected Versions
Versions up to 1.2.0
Next Step
Update to 1.2.1 or newer if supported.