PT-2026-51671 · WordPress · Advanced Contact Form 7 Db
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Advanced Contact Form 7 - Compact DB versions prior to 1.0.1
Description
Unauthenticated attackers can delete arbitrary contact form submission entries stored in the
wp cf7cdb data table. This occurs because the cf7cdb ajax delete user() function lacks nonce verification, capability checks, and ownership validation. The handler is registered for both wp ajax cf7cdb delete and wp ajax nopriv cf7cdb delete endpoints, allowing the deletion of data by iterating through sequential primary-key IDs provided as an integer ID.Recommendations
Update Advanced Contact Form 7 - Compact DB to a version newer than 1.0.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Contact Form 7 Db