Critical 9.6
2025-10-28≤ 1.3.2
CVE-2025-4665
Minimum safe version
1.3.2
Update to 1.3.2 or later to address 9 fixable vulnerabilities
CVE-2025-4665
WordPress Contact Form 7 Database Addon – CFDB7 Plugin <= 1.3.1 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-3870
Contact Form 7 Database Addon <= 1.2.5.3 - SQL Injection
Contact Form 7 Database Addon < 1.2.5.4 - Authenticated SQL Injections
CVE-2022-3634
WordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.5.3 - Insufficient Input Sanitization Leading To Authenticated SQL Injection (SQLi) vulnerability
CVE-2021-24144
CVE-2021-36886
CVE-2021-36885