Input validation vulnerability in Admin side data storage for Contact Form 7 1.1.1

The data storage used by the Admin side of Contact Form 7 plugin for WordPress has a security flaw that allows hackers to access sensitive information. This is because the ‘form-id’ parameter is not properly protected and can be manipulated to add extra SQL queries. This vulnerability exists in all versions of the plugin, up to version 1.1.1. This means that attackers who have administrator-level access or higher can use this loophole to extract confidential data from the database.

Detected in:

Admin side data storage for Contact Form 7 open vulnerable versions: >= * <= 1.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.