CVE · Medium

CVE-2021-36886 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-36886 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.1 Cross-Site Request Forgery (CSRF) Medium 6.5 < 1.2.6.1 1.2.6.1 2021-11-12

CVE-2021-36886

The Contact Form 7 Database Addon CFDB7 plugin up to version 1.2.5.9 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by tricking authenticated users into visiting malicious web pages. The flaw was identified in Ex.Mi through Patchstack and has been resolved in version 1.2.6.1 and later. This vulnerability affects all installations running the vulnerable plugin versions without the necessary security updates.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.