VYPR

Advanced Contact Form 7 - Compact DB

by WordPress

Source repositories

CVEs (8)

  • CVE-2021-24905HigMar 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server.…

  • CVE-2026-12094MedJun 24, 2026
    risk 0.34cvss 5.3epss 0.00

    The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() function in versions up to, and including, 1.0.0. The handler is registered against both…

  • CVE-2024-3723MedJun 11, 2024
    risk 0.34cvss 5.3epss 0.00

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive…

  • CVE-2022-29408MedMay 25, 2022
    risk 0.31cvss 4.7epss 0.01

    Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress.

  • CVE-2026-0811MedApr 8, 2026
    risk 0.28cvss 5.4epss 0.00

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is due to missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This makes it possible for…

  • CVE-2024-4319MedJun 11, 2024
    risk 0.27cvss 5.3epss 0.00

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in versions up to, and including, 2.0.2. This makes it possible for unauthenticated attackers to download…

  • CVE-2026-0814MedApr 8, 2026
    risk 0.21cvss 4.3epss 0.00

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-57669MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.