Advanced Contact form 7 DB <= 2.0.2 - Sensitive Information Exposure
Strategic Overview
- Status
- Patched in 2.0.3
- Affected Plugin
- Advanced Contact form 7 DB
- Affected Version
<= 2.0.2- CVSS
- 5.3Medium
- Weakness type
- CWE-922 · Insecure Storage of Sensitive Information
- CVE
CVE-2024-3723
At a glance
CVE-2024-3723 is a medium-severity Insecure Storage of Sensitive Information vulnerability in the Advanced Contact form 7 DB WordPress plugin, affecting versions <= 2.0.2. It carries a CVSS score of 5.3 (reachable over the network; low attack complexity). Exploitation requires no authentication. The issue is fixed in version 2.0.3; sites on affected versions should update now. Disclosed June 2024, reported by Tim Coen.
Vulnerability Overview
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no privileges on the target site, and no interaction from a victim user.
CWE-922: Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Remediation
Update to version 2.0.3, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Advanced Contact form 7 DB 2.0.3 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Advanced Contact form 7 DB
- 9.8CVE-2019-13571: Advanced Contact Form 7 DB <= 1.6.2 SQL Injection
CVE-2019-13571 - 8.8CVE-2021-24905: Advanced Contact form 7 DB Arbitrary File Deletion
CVE-2021-24905 - 8.5Advanced Contact form 7 DB <= 1.6.0 SQL Injection
- 7.5CVE-2024-45293: PHPSpreadsheet Library < 2.3.0 XXE Injection
CVE-2024-45293 - 6.1CVE-2022-29408: Advanced Contact form 7 DB <= 1.8.7 Stored XSS
CVE-2022-29408 - 5.4CVE-2026-0811: Advanced CF7 DB <= 2.0.9 CSRF to Form Entry Deletion
CVE-2026-0811 - 5.3CVE-2024-4319: Advanced… Unauthenticated Information Disclosure
CVE-2024-4319 - 4.3CVE-2026-18594: Advanced Contact form 7 DB Authenticated (Custom+)
CVE-2026-18594
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C