Junglewise Threat Intelligence

CVE-2026-57669: Vsourz Digital Advanced Contact form 7 DB broken access control

CVE-2026-57669 · Severity: medium · CVSS 6.5 · Published 2026-07-02

Technologies: Vsourz Digital Advanced Contact form 7 DB. Vendors: Vsourz Digital.

Executive brief

The Advanced Contact form 7 DB plugin for WordPress, which stores and manages form submissions, contains a security flaw that allows low-privileged users to access data they should not see. An attacker with a basic 'Subscriber' account could exploit this to view sensitive information submitted by other users through website contact forms. This could lead to the exposure of private customer data and potential regulatory compliance issues.

Technical details

A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Advanced Contact form 7 DB plugin for WordPress in versions up to and including 2.0.9. The flaw stems from insufficient permission checks on functions handling database records. An authenticated attacker with Subscriber-level privileges can exploit this over the network to retrieve sensitive information from the contact form database. The issue is resolved in version 2.1.0, which implements proper authorization checks.

Affected products

  • Vsourz Digital Advanced Contact form 7 DB <= 2.0.9

Timeline

  • 2026-02-09: other: Reported by researcher timomangcut
  • 2026-06-30: advisory: Patchstack advisory published
  • 2026-07-02: disclosed: NVD publication date
  • 2026-06-30: patched: Version 2.1.0 released to address the vulnerability

References