Executive brief
The Advanced Contact form 7 DB plugin for WordPress fails to properly authorize user actions before allowing CSV imports. An authenticated attacker with lower privilege levels (custom-level access or higher) could import forged contact form submissions into any Contact Form 7 form, potentially corrupting business records, creating false leads, or manipulating form data used in business operations.
Technical details
This vulnerability is an authorization bypass (CWE-639) in the CSV import functionality of the Advanced Contact form 7 DB plugin. The plugin fails to properly verify user permissions before processing CSV uploads in the import_cf7_csv.php and import_cf7_entry.class.php files. An authenticated attacker with custom-level access or higher can bypass authorization checks and inject arbitrary submission records into any Contact Form 7 form. The vulnerability requires authentication and valid plugin access but does not require administrative privileges. Patches are available in versions above 2.1.3.
Affected products
- WordPress Plugin Developers Advanced Contact form 7 DB up to and including 2.1.3
Timeline
- 2026-09-10: disclosed