MEDIUM (5.0)
    Plugin

    Unauthorized Data Access in Advanced Contact Form 7 DB Plugin

    Published Date: 4/8/2026
    CVE ID: CVE-2026-0814

    Summary

    The Advanced Contact Form 7 DB plugin up to version 2.0.9 allows unauthorized data exports due to insufficient user permission checks. Authenticated attackers with Subscriber-level access can exploit this flaw to export form submissions.

    Vulnerability Details

    This vulnerability is present in the Advanced Contact Form 7 DB plugin for WordPress, affecting all versions up to and including 2.0.9. The issue arises from the lack of proper capability checks in the 'vsz_cf7_export_to_excel' function. As a result, users with minimal privileges, such as Subscriber-level roles, can gain unauthorized access to export form submission data into Excel files. This could lead to data exposure, privacy violations, or unauthorized data processing by individuals who normally should not have access to such information. The vulnerability poses a potential risk to sites using this plugin, especially those collecting sensitive data through contact forms. Regular capability checks and access controls are critical in plugins handling data export functionalities.

    Recommendations

    Administrators should immediately restrict export functions to higher privilege roles by introducing capability checks in the plugin's code. Until a patched version is available, consider disabling the export function by removing or commenting out the 'vsz_cf7_export_to_excel' functionality in the plugin temporarily. Monitor server logs for unusual export activities and limit user access to the minimal necessary permissions.

    Available Fixes

    Last Updated: 4/10/2026
    Jedar

    Jedar for Digital Rights is a non-profit organization dedicated to protecting digital freedoms, enhancing online privacy, and promoting secure digital practices for vulnerable communities worldwide.

    Follow Us

    All Rights Reserved © 2026 Jedar for Digital Rights.

    Cookie Preferences

    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.

    Learn More