PT-2026-51671 · WordPress · Advanced Contact Form 7 Db

·

CVE-2026-12094

·

Published

2026-06-24

·

Updated

2026-07-02

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Advanced Contact Form 7 - Compact DB versions prior to 1.0.1
Description Unauthenticated attackers can delete arbitrary contact form submission entries stored in the wp cf7cdb data table. This occurs because the cf7cdb ajax delete user() function lacks nonce verification, capability checks, and ownership validation. The handler is registered for both wp ajax cf7cdb delete and wp ajax nopriv cf7cdb delete endpoints, allowing the deletion of data by iterating through sequential primary-key IDs provided as an integer ID.
Recommendations Update Advanced Contact Form 7 - Compact DB to a version newer than 1.0.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12094

Affected Products

Advanced Contact Form 7 Db