The Advanced Contact form 7 DB plugin for WordPress has a security issue where sensitive information can be accessed by unauthorized individuals. This affects all versions of the plugin up to 2.0.2 and can be done through the wp-content/uploads/advanced-cf7-upload directory. This means that hackers can potentially retrieve any sensitive data that was uploaded through the plugin’s form without having to log in.