cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontact-form-entries contact-form-entries

Direction: ascending
Jun 07, 2024

Database for Contact Form 7, WPforms, Elementor forms # CVE-2021-25080

CVE, Research URL

CVE-2021-25080

Date
Jan 24, 2022
Research Description
The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against logged in admins viewing the created entry
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2021-25079

CVE, Research URL

CVE-2021-25079

Date
Jan 24, 2022
Research Description
The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputting them back in the admin page
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2022-3604

CVE, Research URL

CVE-2022-3604

Date
Jan 16, 2024
Research Description
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2023-31212

CVE, Research URL

CVE-2023-31212

Date
Oct 31, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Database for Contact Form 7, WPforms, Elementor forms contact-form-entries allows SQL Injection.This issue affects Database for Contact Form 7, WPforms, Elementor forms: from n/a through 1.3.0.
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2023-33311

CVE, Research URL

CVE-2023-33311

Date
May 29, 2023
Research Description
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CRM Perks Contact Form Entries plugin <= 1.3.0 versions.
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2024-2030

CVE, Research URL

CVE-2024-2030

Date
Mar 13, 2024
Research Description
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2024-3715

CVE, Research URL

CVE-2024-3715

Date
May 02, 2024
Research Description
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
Min -, max -.
Status
vulnerable

Database for Contact Form 7, WPforms, Elementor forms # CVE-2024-1069

CVE, Research URL

CVE-2024-1069

Date
Jan 31, 2024
Research Description
The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
Min -, max -.
Status
vulnerable
Aug 14, 2025

Database for Contact Form 7, WPforms, Elementor forms # CVE-2025-7384

CVE, Research URL

CVE-2025-7384

Date
Aug 13, 2025
Research Description
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.
Affected versions
Min -, max -.
Status
vulnerable