What the vulnerability does
01Description
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced-cf7-upload directory. This makes it possible for unauthenticated attackers to extract sensitive data uploaded via this plugin through a form.
Explanation of Vulnerability in Simple Terms
02Summary
Advanced Contact Form 7 DB versions up to 2.0.2 expose form submission data without proper access controls. An unauthenticated attacker can read sensitive information submitted through contact forms, including names, email addresses, and message content. Update to a version newer than 2.0.2 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read contact form submissions and other sensitive data without authentication.
Potential impact on your site
04Site Impact
Visitor contact form data, including names and emails, is exposed to anyone on the internet.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 11, 2024
CVE published
April 8, 2026
Record updated