Input validation vulnerability in Database for Contact Form 7, WPforms, Elementor forms 1.3.3

The contact form plugin for WordPress, called “Database for Contact Form 7, WPforms, and Elementor forms,” has a security issue that allows attackers to insert harmful code into webpages. This can happen when someone uses the plugin’s special codes in versions 1.3.3 and earlier. The problem is that the plugin doesn’t properly check the information it gets from users, so attackers with certain permissions can put their own code on any page that uses the plugin.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.