Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export
Database for Contact Form 7, WPforms, Elementor forms
Minimum safe version
1.5.0
Update to 1.5.0 or later to address 19 fixable vulnerabilities
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'
WordPress Contact Form Entries Plugin <= 1.4.9 is vulnerable to Broken Access Control
Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion
CVE-2024-3715
CVE-2024-2030
CVE-2024-1069
CVE-2023-33311
CVE-2023-31212
Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 - Reflected Cross-Site Scripting
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
CVE-2022-3604
Contact Form Entries < 1.2.1 - Reflected Cross-Site Scripting
Multiple Plugins from CRM Perks - Reflected Cross-Site Scripting
WordPress Contact Form Entries plugin <= 1.2.3 - Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities
WordPress Contact Form Entries plugin <= 1.2.3 - Authenticated Persistent Cross-Site Scripting (XSS) vulnerability
WordPress Contact Form Entries plugin <= 1.2.3 - Unauthenticated Persistent Cross-Site Scripting (XSS) vulnerability
CVE-2021-25080
CVE-2021-25079