CVE-2026-14870

CVE-2026-14870: Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id

Vendor Unknown
Product Database for Contact Form 7, WPforms, Elementor forms
Published July 28, 2026
Last update July 28, 2026

CVSS base score

What the vulnerability does

01Description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Key dates

02Disclosure timeline

July 28, 2026 CVE published
July 28, 2026 Record updated