WordPress · Database For Contact Form 7 · CVE-2026-14870
**Name of the Vulnerable Software and Affected Versions**
Database for Contact Form 7, WPforms, Elementor forms versions prior to 1.5.3
**Description**
This issue involves a Reflected Cross-Site Scripting (XSS) flaw where the plugin fails to properly sanitize and escape the `form id` parameter before reflecting it on an administration page. This could allow an attacker to execute malicious scripts in the context of high-privilege users, such as administrators.
**Recommendations**
Update Database for Contact Form 7, WPforms, Elementor forms to version 1.5.3 or later.