Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-3831

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Apr 01, 2026
Vendor unknown

Description

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract all form submissions - including names, emails, phone numbers.

References