Vulnerabilities and security researches forsb-elementor-contact-form-db sb-elementor-contact-form-db
Direction: descendingFeb 28, 2026
Contact Form DB – Elementor # CVE-2026-25320
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 19, 2026
- Research Description
- Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Contact Form DB: from n/a through <= 2.1.3.
- Affected versions
-
max 2.1.3.
- Status
-
vulnerable
Jun 07, 2024
Contact Form DB – Elementor # CVE-2022-2116
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 15, 2022
- Research Description
- The Contact Form DB WordPress plugin before 1.8.0 does not sanitise and escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected versions
-
max 1.8.0.
- Status
-
vulnerable
Contact Form DB – Elementor # CVE-2021-3133
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 13, 2021
- Research Description
- The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages.
- Affected versions
-
max 1.6.
- Status
-
vulnerable