CVE-2026-9145 MEDIUM

CVE-2026-9145: Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'

Vendor Crmperks
Product Database for Contact Form 7, WPforms, Elementor forms
Weakness CWE-22 · Path traversal
Published July 2, 2026
Last update July 2, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy() without validating that the value corresponds to a legitimately uploaded file — when no file is present in $_FILES, raw_value reflects the attacker-controlled POST string. copy() accepts both local filesystem paths and URL sources, so the attacker can target any file readable by the PHP process or supply an attacker-controlled remote URL. Elementor Pro is a prerequisite for triggering the code path (it owns the elementor_pro/forms/new_record hook and populates the Form_Record object), but the bug itself is entirely in Contact Form Entries' handler. This could allow unauthenticated attackers to disclose arbitrary files on the affected site's server. The file is copied to a directory unknown to the attacker; the hashed directory name provides defense-in-depth but is generated from non-cryptographic sources (uniqid() + rand()) and should not be relied upon as the primary mitigation.

Explanation of Vulnerability in Simple Terms

02Summary

The Database for Contact Form 7, WPforms, and Elementor forms plugin contains a path traversal vulnerability that allows attackers to read files outside the intended directory. An attacker can access sensitive files on the server without authentication. The vulnerability affects versions up to 1.5.1 and requires specific conditions to exploit.

What an attacker can do

03Attacker Capabilities

Read arbitrary files from the server, including configuration files and other sensitive data.

Potential impact on your site

04Site Impact

Attackers could access sensitive files like database credentials, API keys, or other configuration data stored on your server.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication required, but exploitation requires specific conditions (high attack complexity).

Key dates

06Disclosure timeline

July 2, 2026 CVE published
July 2, 2026 Record updated

Related vulnerabilities

08Related CVE