Junglewise Threat Intelligence

CVE-2026-6831: Advanced Contact form 7 DB authorization bypass in shortcode

CVE-2026-6831 · Severity: medium · CVSS 6.5 · Published 2026-09-23

Executive brief

The Advanced Contact form 7 DB plugin for WordPress fails to properly authorize users before allowing access to contact form submissions. An authenticated attacker with a Contributor-level WordPress account or higher can read all submitted Contact Form 7 data through a shortcode, potentially exposing sensitive customer inquiries and personal information collected via contact forms.

Technical details

The plugin lacks authorization checks when processing the 'acf7db' shortcode, allowing authenticated users to bypass intended access controls. An attacker with Contributor-level or higher permissions can directly access and read all Contact Form 7 submission data without proper capability verification. The vulnerability affects all versions up to 2.0.9 and is fixed in version 2.1.2.

Affected products

  • Advanced CF7 DB Advanced Contact form 7 DB up to and including 2.0.9

Timeline

  • 2026-09-23: disclosed

References