Plugin Vulnerability Hub
Plugin 13 known issues Latest disclosed Mar 31, 2026

Database for Contact Form 7, WPforms, Elementor forms Vulnerabilities

Review known vulnerability records for the WordPress plugin Database for Contact Form 7, WPforms, Elementor forms (`contact-form-entries`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-3831, CVE-2026-2599 and CVE-2026-0825, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
13
High or Critical
7
Patch Coverage
100%
Last Updated
Apr 01, 2026
Related Security Guides

Use these guides while reviewing Database for Contact Form 7, WPforms, Elementor forms fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Database for Contact Form 7, WPforms, Elementor forms remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
11
1. Match the Package
Confirm the installed WordPress plugin slug is contact-form-entries before acting on any CVE from this cluster.
2. Sort by Severity
Start with 7 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
13 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Database for Contact Form 7, WPforms, Elementor forms CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
12
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2026-2599
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP...
Vulnerability Versions up to 1.4.7 1.4.8 CVSS 9.8
CVE-2025-7384
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP...
Remote Code Execution Versions up to 1.4.3 1.4.4 CVSS 9.8
CVE-2023-31212
Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via short...
SQL Injection Versions up to 1.3.0 1.3.1 CVSS 8.8
CVE-2024-3715
Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Sto...
Stored Cross-Site Scripting Versions up to 1.3.8 1.3.9 CVSS 7.2
CVE-2024-1069
Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload
Remote Code Execution Versions up to 1.3.2 1.3.3 CVSS 7.2
CVE-2022-3604
Contact Form Entries <= 1.2.9 - CSV Injection
Vulnerability Versions up to 1.2.9 1.3.0 CVSS 7.2
CVE-2021-25080
Contact Form Entries <= 1.1.6 - Unauthenticated Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions up to 1.1.6 1.1.7 CVSS 7.2
CVE-2024-2030
Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contr...
Stored Cross-Site Scripting Versions up to 1.3.3 1.3.4 CVSS 6.4
CVE-2026-2599 Critical 1.4.8
CVE-2026-2599 Database for Contact Form 7, WPforms, Elementor forms Vulnerability

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'

CVE-2025-7384 Critical 1.4.4
CVE-2025-7384 Database for Contact Form 7, WPforms, Elementor forms Remote Code Execution

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion

CVE-2023-31212 High 1.3.1
CVE-2023-31212 Database for Contact Form 7, WPforms, Elementor forms SQL Injection

Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via shortcode

CVE-2024-3715 High 1.3.9
CVE-2024-3715 Database for Contact Form 7, WPforms, Elementor forms Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-1069 High 1.3.3
CVE-2024-1069 Database for Contact Form 7, WPforms, Elementor forms Remote Code Execution

Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload

CVE-2022-3604 High 1.3.0
CVE-2022-3604 Database for Contact Form 7, WPforms, Elementor forms Vulnerability

Contact Form Entries <= 1.2.9 - CSV Injection

CVE-2021-25080 High 1.1.7
CVE-2021-25080 Database for Contact Form 7, WPforms, Elementor forms Stored Cross-Site Scripting

Contact Form Entries <= 1.1.6 - Unauthenticated Stored Cross-Site Scripting

CVE-2024-2030 Medium 1.3.4
CVE-2024-2030 Database for Contact Form 7, WPforms, Elementor forms Stored Cross-Site Scripting

Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Database for Contact Form 7, WPforms, Elementor forms so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
13 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
2 critical and 5 high severity findings.
Recent CVEs
CVE-2026-3831, CVE-2026-2599 and CVE-2026-0825
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Database for Contact Form 7, WPforms, Elementor forms

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-3831
CVE-2026-3831: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated...

Published
Mar 31, 2026
Patched Release
1.5.0
Affected Versions
Versions up to 1.4.9
Next Step
Update to 1.5.0 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-2599
CVE-2026-2599: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attac...

Published
Mar 04, 2026
Patched Release
1.4.8
Affected Versions
Versions up to 1.4.7
Next Step
Update to 1.4.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0825
CVE-2026-0825: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers...

Published
Jan 27, 2026
Patched Release
1.4.6
Affected Versions
Versions up to 1.4.5
Next Step
Update to 1.4.6 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-7384
CVE-2025-7384: Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated atta...

Published
Aug 12, 2025
Patched Release
1.4.4
Affected Versions
Versions up to 1.4.3
Next Step
Update to 1.4.4 or newer if supported.
Plugin High Patched: Yes CVE-2024-3715
CVE-2024-3715: Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

Published
Apr 22, 2024
Patched Release
1.3.9
Affected Versions
Versions up to 1.3.8
Next Step
Update to 1.3.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2030
CVE-2024-2030: Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attrib...

Published
Mar 06, 2024
Patched Release
1.3.4
Affected Versions
Versions up to 1.3.3
Next Step
Update to 1.3.4 or newer if supported.
Plugin High Patched: Yes CVE-2024-1069
CVE-2024-1069: Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities...

Published
Jan 30, 2024
Patched Release
1.3.3
Affected Versions
Versions up to 1.3.2
Next Step
Update to 1.3.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-33311
CVE-2023-33311: Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via vx-entries shortcode

The Contact Form Entries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vx-entries' shortcode attributes in versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack...

Published
May 22, 2023
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin High Patched: Yes CVE-2023-31212
CVE-2023-31212: Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via shortcode

The Contact Form Entries plugin for WordPress is vulnerable to generic SQL Injection via the plugin's shortcode attributes in versions up to, and including, 1.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu...

Published
May 22, 2023
Patched Release
1.3.1
Affected Versions
Versions up to 1.3.0
Next Step
Update to 1.3.1 or newer if supported.
Plugin High Patched: Yes CVE-2022-3604
CVE-2022-3604: Contact Form Entries <= 1.2.9 - CSV Injection

The Contact Form Entries plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.9 when outputting to a CSV file. This allows low-level attackers to embed untrusted input contact forms that will be present in exported CSV files, which can result...

Published
Oct 21, 2022
Patched Release
1.3.0
Affected Versions
Versions up to 1.2.9
Next Step
Update to 1.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-25079
CVE-2021-25079: Contact Form Entries <= 1.2.3 - Reflected Cross-Site Scripting

The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page

Published
Nov 14, 2021
Patched Release
1.2.4
Affected Versions
Versions up to 1.2.3
Next Step
Update to 1.2.4 or newer if supported.
Plugin Medium Patched: Yes
Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 - Reflected Cross-Site Scripting

The Contact Form Entries – Contact Form 7, WPforms and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This...

Published
Aug 24, 2021
Patched Release
1.2.1
Affected Versions
Versions up to 1.2.0
Next Step
Update to 1.2.1 or newer if supported.