๐Ÿ” CVE Alert

CVE-2026-14872

UNKNOWN 0.0

Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.

Vendor unknown
Product database for contact form 7, wpforms, elementor forms
Published Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown database for contact form 7, wpforms, elementor forms

Be the first to know when new unknown vulnerabilities affecting unknown database for contact form 7, wpforms, elementor forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Database for Contact Form 7, WPforms, Elementor forms
0 < 1.5.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/557414c2-70b9-4466-8727-d8a2c9a8a502/

Credits

Andrew Lyons WPScan