Advanced Contact form 7 DB <= 2.0.8 & Import any XML, CSV or Excel File to WordPress <= 3.8.0 - Use of Vulnerable Component (PHPExcel)

2025-04-07 00:00
Anonymous

Strategic Overview

Status
Patched in 2.0.9
Affected Version<= 2.0.8
CVSS3.7Low
CVECVE-2014-2054
View all Advanced Contact form 7 DB vulnerabilities

Vulnerability Overview

Multiple plugins for WordPress utilize a vulnerable dependency (PHPExcel) in various versions. No vulnerabilities have been confirmed exploitable in either plugin, however, an update is still recommended for both.

Technical Analysis

REMEDIATION: Update to version 2.0.9, or a newer patched version --- IDENTIFIER: CWE-1395 (Dependency on Vulnerable Third-Party Component) The product has a dependency on a third-party component that contains one or more known vulnerabilities.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C