Junglewise Threat Intelligence

CVE-2026-13425: code4life Database for CF7 stored XSS via array form field values

CVE-2026-13425 · Severity: high · CVSS 7.2 · Published 2026-07-29

Executive brief

The Database for CF7 plugin for WordPress, which stores submissions from Contact Form 7, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website's database. Because the plugin fails to properly clean data submitted through public forms, an unauthenticated attacker can submit specially crafted information that executes harmful code when an administrator views the form entries. This could lead to unauthorized actions being performed in the context of a site administrator's session, potentially compromising the website.

Technical details

The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on form field values. Unauthenticated attackers can exploit this by submitting array-structured input (e.g., your-name[]) to the public Contact Form 7 REST API endpoint (/wp-json/contact-form-7/v1/contact-forms/{id}/feedback). The plugin stores this data using $wpdb INSERT with serialize() into a custom 'wp_cf7db' table, which bypasses standard WordPress save-time filtering mechanisms like wp_kses. When an administrative user views the submitted data, the injected scripts execute in their browser session. The vulnerability is present in all versions up to and including 1.2.6.

Affected products

  • code4life Database for CF7 <= 1.2.6

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References