Awesome Contact Form7 for Elementor
Awesome Contact Form7 for Elementor has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Awesome Contact Form7 for Elementor has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Awesome Contact Form7 for Elementor is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-49319Awesome Contact Form7 for Elementor <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Awesome Contact Form7 for Elementor
Author
B.M. Rafiul Alam
Adds Awesome Contact Form7 for Elementor that are specifically designed to be used in conjunction with the Elementor Page Builder and Contact form7. Video tutorial link: Make a cool contact form in 5 minutes with Awesome Contact Form7 for Elementor
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C