Junglewise Threat Intelligence

CVE-2026-18594: Advanced Contact form 7 DB authorization bypass

CVE-2026-18594 · Severity: medium · CVSS 4.3 · Published 2026-09-10

Technologies: WordPress Plugin Developers Advanced Contact form 7 DB.

Executive brief

The Advanced Contact form 7 DB plugin for WordPress fails to properly authorize user actions before allowing CSV imports. An authenticated attacker with lower privilege levels (custom-level access or higher) could import forged contact form submissions into any Contact Form 7 form, potentially corrupting business records, creating false leads, or manipulating form data used in business operations.

Technical details

This vulnerability is an authorization bypass (CWE-639) in the CSV import functionality of the Advanced Contact form 7 DB plugin. The plugin fails to properly verify user permissions before processing CSV uploads in the import_cf7_csv.php and import_cf7_entry.class.php files. An authenticated attacker with custom-level access or higher can bypass authorization checks and inject arbitrary submission records into any Contact Form 7 form. The vulnerability requires authentication and valid plugin access but does not require administrative privileges. Patches are available in versions above 2.1.3.

Affected products

  • WordPress Plugin Developers Advanced Contact form 7 DB up to and including 2.1.3

Timeline

  • 2026-09-10: disclosed

References