CVE-2026-14872

CVE-2026-14872: Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injection via id Parameter

Vendor Unknown
Product Database for Contact Form 7, WPforms, Elementor forms
Published August 4, 2026
Last update August 4, 2026

CVSS base score

What the vulnerability does

01Description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.

Key dates

02Disclosure timeline

August 4, 2026 CVE published
August 4, 2026 Record updated