CVE-2026-14870
Received Received - Intake

Reflected Cross-Site Scripting in Database for Contact Form 7, WPForms, Elementor Forms WordPress Plugin

Vulnerability report for CVE-2026-14870, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: WPScan

Description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Reflected Cross-Site Scripting (XSS) vulnerability in the Database for Contact Form 7, WPforms, Elementor forms WordPress plugin versions before 1.5.3. The plugin fails to properly sanitize and escape the form_id parameter, allowing attackers to inject malicious JavaScript code that executes when an admin views a crafted URL.

Detection Guidance

To detect this vulnerability, check if you are using the Database for Contact Form 7, WPforms, Elementor forms WordPress plugin version prior to 1.5.3. You can do this by logging into your WordPress admin panel, navigating to the plugins section, and verifying the installed version of the plugin.

Impact Analysis

An attacker could trick an admin into clicking a malicious link, executing arbitrary JavaScript in their session. This could lead to session hijacking, unauthorized actions on the site, or theft of sensitive data like admin credentials.

Compliance Impact

This vulnerability could compromise user data confidentiality, potentially violating GDPR (data protection) and HIPAA (health data privacy) requirements. Unauthorized access via XSS may lead to data breaches, triggering compliance violations and legal penalties.

Mitigation Strategies

Immediately update the Database for Contact Form 7, WPforms, Elementor forms plugin to version 1.5.3 or later. If updating is not possible, consider disabling the plugin temporarily until an update can be applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14870. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart