CVE · Medium

CVE-2024-3870 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3870 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.2.7 1.2.7 2024-04-26

CVE-2024-3870

The Contact Form 7 Database Addon – CFDB7 plugin contains a sensitive information exposure flaw affecting versions 1.2.6.8 and earlier through the cfdb7_before_send_mail function. An attacker without authentication can exploit this vulnerability to access and retrieve sensitive user data, including personally identifiable information, from files that users have uploaded through the form.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.