Junglewise Threat Intelligence

CVE-2026-0814: vsourz1td Advanced Contact form 7 DB missing authorization

CVE-2026-0814 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Vsourz1td Advanced Contact form 7 DB.

Executive brief

The Advanced Contact form 7 DB plugin for WordPress, which stores and manages form submissions, contains a security flaw that allows unauthorized users to access sensitive data. An attacker with a basic user account on the website can export all contact form submissions into an Excel file. This could lead to the exposure of private customer information and communication history.

Technical details

The vulnerability is classified as a Missing Authorization (CWE-862) issue within the 'vsz_cf7_export_to_excel' function of the Advanced Contact form 7 DB plugin. Because the plugin fails to perform a capability check (such as current_user_can()) on this specific function, any authenticated user, including those with the lowest 'Subscriber' permissions, can trigger the export process. An attacker can exploit this by sending a crafted request to the server to download an Excel file containing all stored form submissions. The issue affects all versions of the plugin up to and including 2.0.9. A patch has been identified in subsequent changesets.

Affected products

  • vsourz1td Advanced Contact form 7 DB up to, and including, 2.0.9

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References