CVE-2026-14870
7.1Contact Form 7, WPforms, Elementor forms (Plugin Author) · Database for Contact Form 7, WPforms, Elementor forms
A Reflected Cross-Site Scripting (XSS) vulnerability in the Database for Contact Form 7, WPforms, Elementor forms plugin allows attackers to execute malicious scripts in an admin session.
Executive summary
The Database for Contact Form 7, WPforms, Elementor forms plugin is vulnerable to Reflected Cross-Site Scripting, which could allow an attacker to compromise high-privilege administrative accounts.
Vulnerability
The plugin fails to properly sanitize and escape input parameters before reflecting them within administrative pages. This flaw allows an unauthenticated attacker to inject malicious JavaScript, which executes when a high-privilege user, such as an administrator, views the affected page.
Business impact
Successful exploitation allows an attacker to perform actions on behalf of an administrator, potentially leading to full site compromise, unauthorized data access, or the injection of persistent malicious content. With a CVSS score of 7.1, this vulnerability presents a significant risk to the integrity and confidentiality of the WordPress environment.
Remediation
Immediate Action: Update the Database for Contact Form 7, WPforms, Elementor forms plugin to version 1.5.3 or later immediately.
Proactive Monitoring: Review administrative access logs for unusual activity or unexpected script execution patterns occurring within the plugin dashboard.
Compensating Controls: Deploy a Web Application Firewall (WAF) with robust XSS protection rules to detect and block malicious payloads targeting the reflected parameters.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for administrative account takeover, this vulnerability poses a high risk to organizational security. Administrators must prioritize updating the affected plugin to version 1.5.3 immediately to eliminate the underlying injection vector and secure the administrative interface.
Sources
Originally found and disclosed by Luca Jungnickel, with WPScan (coordinator), per the CVE Program record.