Database for Contact Form 7, WPforms, Elementor forms

Database for Contact Form 7, WPforms, Elementor forms has 20 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2026; all 20 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 2 critical and 8 high. 2026 was the busiest year with 9 disclosures.

The most common weakness is Cross-Site Scripting, behind 9 of the records (45%). Other recurring categories include Deserialization Of Untrusted Data, Missing Authorization.

Every one of the 20 issues recorded for Database for Contact Form 7, WPforms, Elementor forms has a vendor fix available, so running the current release closes all known holes.

16 independent researchers contributed these findings, most of them (2) reported by daroo. Database for Contact Form 7, WPforms, Elementor forms is installed on roughly 60,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891018.08.2018Today05.01.20217.2Contact Form Entries <= 1.1.6 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 05.01.202124.08.20216.1Contact Form Entries – Contact Form 7, WPforms and more <= 1.2.0 - Reflected Cross-Site Scripting CVSS 6.1 · 24.08.202126.08.20216.1CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting CVSS 6.1 · 26.08.202114.11.20216.1Contact Form Entries <= 1.2.3 - Reflected Cross-Site Scripting CVSS 6.1 · 14.11.202121.10.20227.2Contact Form Entries <= 1.2.9 - CSV Injection CVSS 7.2 · 21.10.202222.05.20236.4Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via vx-entries shortcode CVSS 6.4 · 22.05.20238.8Contact Form Entries <= 1.3.0 - Authenticated (Contributor+) SQL Injection via shortcode CVSS 8.8 · 22.05.202330.01.20247.2Contact Form Entries <= 1.3.2 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 30.01.202406.03.20246.4Database for Contact Form 7, WPforms, Elementor forms <= 1.3.3 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode CVSS 6.4 · 06.03.202422.04.20247.2Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 22.04.202412.08.20259.8Database for Contact Form 7, WPforms, Elementor forms <= 1.4.3 - Unauthenticated PHP Object Injection to Arbitrary File Deletion CVSS 9.8 · 12.08.202527.01.20265.3Database for Contact Form 7, WPforms, Elementor forms <= 1.4.5 - Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export CVSS 5.3 · 27.01.202604.03.20269.8Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv' CVSS 9.8 · 04.03.202631.03.20264.3Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode CVSS 4.3 · 31.03.202619.06.20268.1Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value CVSS 8.1 · 19.06.202622.06.20268.1Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated PHP Object Injection CVSS 8.1 · 22.06.202601.07.20266.5Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value' CVSS 6.5 · 01.07.202607.07.20266.1Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Reflected Cross-Site Scripting CVSS 6.1 · 07.07.202610.07.20267.2Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 10.07.202627.07.20266.5Database for Contact Form 7, WPforms, Elementor forms <= 1.5.4 - Authenticated (Authenticated+) SQL Injection CVSS 6.5 · 27.07.2026

Strategic Overview

Avg CVSSHigh
7.0/ 10
Patch Coverage100%
Open

0

Fixed

20

Get automatic notifications for all Database for Contact Form 7, WPforms, Elementor forms vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-2599

Database for Contact Form 7, WPforms, Elementor forms <= 1.4.7 - Unauthenticated PHP Object Injection via 'download_csv'

Read the full analysis

Vulnerability Records

20 records
2026-07-27 00:00CVE-2026-14872
6.5
Medium
Andrew LyonsYes
2026-07-10 00:00CVE-2026-57708
7.2
High
darooYes
2026-07-07 00:00CVE-2026-14870
6.1
Medium
Luca JungnickelYes
2026-07-01 21:05CVE-2026-9145
6.5
Medium
Jonah Burgess (CryptoCat)Yes
2026-06-22 00:00CVE-2026-12081
8.1
High
Meher Sudhakar AbbireddiYes
2026-06-19 11:55CVE-2026-9843
8.1
High
darooYes
2026-03-31 12:23CVE-2026-3831
4.3
Medium
Quốc Huy (jtwings)Yes
2026-03-04 00:00CVE-2026-2599
9.8
Critical
Chiao-Lin Yu (Steven Meow)Yes
2026-01-27 17:44CVE-2026-0825
5.3
Medium
Teerachai SomprasongYes
2025-08-12 00:00CVE-2025-7384
9.8
Critical
mikemyersYes
Showing 1–10 of 20 reports
Database for Contact Form 7, WPforms, Elementor forms banner
Latestv1.5.5

Database for Contact Form 7, WPforms, Elementor forms

CRM Perks

Author

CRM Perks

4.8(124)
96/100
Last Updated
2026-09-06 (7d ago)
Active Installs
60,000+
Downloads
1,197,956
Requires WP
3.8+
Requires PHP
5.3+
Tested up to
WP 7.1
Created
2018-08-18 (8y ago)

Contact Form 7 Entries Plugin automatically saves form submissions from Contact Form 7, WPforms, Elementor Forms, CRM Perks Forms and many other popular contact form plugins to wordpress database when anyone submits a form. Learn more our forms builder and entries at crmperks.com Supported Contact Forms Contact Form 7 CRM Perks Forms WPForms Elementor Forms Contact form 7 entries features You can view all contact form entries in default wordpress table form. Search contact form entries by all or specific field. Filter contact form entries by Date. You can mark contact form entries as read or un-read. You can star or un-star contact form entries. Print all or selected contact form entries. You can also print notes related to each contact form entry. Select entries table columns from “Screen Options”. File field of an entry supports multiple files. Add, edit notes to any contact form entry. Display contact form entries on any wordpress page in sortable table form. Export contact form entries in csv format. Why we built this plugin Contact Form 7 is free contact form builder. This free Contact Form 7 Entries plugin adds entries management and all premium features to free wordpress contact forms including contact form 7. You can send entries data to your CRM or mailing lists. WPforms database addon This Plugin saves WPforms entries into wordpress database, you can view and edit any entry. You can also export all entries as csv file. Contact Form 7 Entries Stats This plugin displays contact form 7 submissions summary by contact form on dashboard. You can see all read/un-read entries of all contact forms at one place. Contact Form Entry Notes You can add notes to any contact form entry and you can edit old notes. Also you can select note color to mark it as important or normal. GDPR compliant You can disable storing form entries into database. You can disable storing user’s IP address , Browser , Screen Resolution and OS. Adds all contact form entries of a user when exporting user data using wordpress “Export Personal Data” tool. Deletes all contact form entries of a user when deleting user data using wordpress “Erase Personal Data” tool. Premium Version Features. Following features are available in premium add-ons Get all add-ons and CRM Perks forms. Don’t miss out on any potential leads. Collect data in real time as it is entered on your forms. Search field and Download CSV button for front end entries table. Complete clickable links for file fields in front end entries table. Google Analytics Parameters and Geolocation of a visitor who submitted the form. Lookup lead’s email and phone using email and phone lookup apis. 20+ premium add-ons Get access to all addons and CRM Perks forms Want to send data to crm We have Premium Extensions for 20+ CRMs.View All CRM Extensions Contact Form Klaviyo Plugin Contact Form Google Sheets Plugin Contact Form Streak Plugin Contact Form Freshdesk Plugin Contact Form 7 Pardot

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C