Vulnerabilities and security researches forcontact-form-entries contact-form-entries
Direction: ascendingJun 07, 2024
Database for Contact Form 7, WPforms, Elementor forms # CVE-2021-25080
- CVE, Research URL
- Date
- Jan 24, 2022
- Research Description
- The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2021-25079
- CVE, Research URL
- Date
- Jan 24, 2022
- Research Description
- The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2022-3604
- CVE, Research URL
- Date
- Jan 16, 2024
- Research Description
- The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2023-31212
- CVE, Research URL
- Date
- Oct 31, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2023-33311
- CVE, Research URL
- Date
- May 29, 2023
- Research Description
- Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2024-2030
- CVE, Research URL
- Date
- Mar 13, 2024
- Research Description
- The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2024-3715
- CVE, Research URL
- Date
- May 02, 2024
- Research Description
- The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Database for Contact Form 7, WPforms, Elementor forms # CVE-2024-1069
- CVE, Research URL
- Date
- Jan 31, 2024
- Research Description
- The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Aug 14, 2025
Database for Contact Form 7, WPforms, Elementor forms # CVE-2025-7384
- CVE, Research URL
- Date
- Aug 13, 2025
- Research Description
- The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable