What the vulnerability does
01Description
Missing Authorization vulnerability in code4life Database for CF7 database-for-cf7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database for CF7: from n/a through <= 1.2.4.
Explanation of Vulnerability in Simple Terms
02Summary
Database for CF7 versions up to 1.2.4 lack proper authorization checks, allowing authenticated users with low privileges to disrupt site availability. An attacker with a basic user account can trigger a denial-of-service condition by making requests that consume server resources or crash the database component. This affects sites using the plugin without restricting user access.
What an attacker can do
03Attacker Capabilities
Disrupt site availability by making the database component unavailable or unresponsive.
Potential impact on your site
04Site Impact
Site may become slow or inaccessible if an authenticated user exploits this flaw to overload the database.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site; no special interaction required.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 29, 2026
Record updated