CVE-2026-14870
Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
| Vendor | unknown |
| Product | database for contact form 7, wpforms, elementor forms |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown database for contact form 7, wpforms, elementor forms
Be the first to know when new unknown vulnerabilities affecting unknown database for contact form 7, wpforms, elementor forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Database for Contact Form 7, WPforms, Elementor forms
0 < 1.5.3
References
Credits
Luca Jungnickel WPScan