VYPR

Wp Contact Form 7 Db Handler

by WordPress

CVEs (1)

  • CVE-2026-6455HigMay 28, 2026
    risk 0.53cvss 8.1epss

    The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the…