CVE-2026-14872
Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.
| Vendor | unknown |
| Product | database for contact form 7, wpforms, elementor forms |
| Published | Aug 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown database for contact form 7, wpforms, elementor forms
Be the first to know when new unknown vulnerabilities affecting unknown database for contact form 7, wpforms, elementor forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Database for Contact Form 7, WPforms, Elementor forms
0 < 1.5.5
References
Credits
Andrew Lyons WPScan