CVE-2026-6831
Received Received - Intake

Missing Authorization in Advanced Contact Form 7 DB WordPress Plugin

Vulnerability report for CVE-2026-6831, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Wordfence

Description

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to read all Contact Form 7 submission data via the 'acf7db' shortcode.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
advanced_contact_form_7_db plugin to 2.0.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Advanced Contact Form 7 DB plugin for WordPress. It allows authenticated users with Contributor-level access or higher to read all Contact Form 7 submission data without proper authorization checks. The issue stems from missing authorization in versions up to and including 2.0.9.

Detection Guidance

Check WordPress sites for the Advanced Contact Form 7 DB plugin version 2.0.9 or lower. Look for unauthorized access to Contact Form 7 submission data via the 'acf7db' shortcode. Inspect server logs for unusual queries or access patterns related to this plugin.

Impact Analysis

If you use this plugin, attackers could access sensitive form submission data, including personal or confidential information submitted through Contact Form 7. This could lead to data breaches or privacy violations.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or protected health information. Organizations may face legal penalties or fines for failing to protect sensitive data.

Mitigation Strategies

Update the Advanced Contact Form 7 DB plugin to the latest version. Remove or disable the plugin if updates are unavailable. Restrict user roles to prevent Contributor-level access from executing unauthorized actions. Monitor for suspicious activity in Contact Form 7 submission data access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6831. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart