PLUGIN SECURITY

Is Contact Form Cfdb7 safe?

Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.

What this plugin does

  • Slug: contact-form-cfdb7
  • Author: Arshid
  • 600000+ active installs
  • 100/100 rating (1874 reviews on wordpress.org)
  • 8852023 all-time downloads
  • On WordPress.org since 2017-03-18

cf7CF7 Databasecontact form 7contact form 7 dbwpcf7

Maintenance status

  • Latest known version: 1.4.0
  • Last updated: 2026-08-20 4:59am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.0+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

6 known CVEs on file for Contact Form Cfdb7.

CVE Vulnerability Type Severity Affected Fixed in Published Status
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] <= 1.3.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.6 < 1.3.2 1.3.2 2025-10-28 ✓ fixed in latest
CVE-2024-3870 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 1.2.7 1.2.7 2024-04-26 ✓ fixed in latest
CVE-2022-3634 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.5 Improper Neutralization of Formula Elements in a CSV File Critical 9.8 < 1.2.6.5 1.2.6.5 2022-10-27 ✓ fixed in latest
CVE-2021-36885 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.2.6.2 1.2.6.2 2021-11-12 ✓ fixed in latest
CVE-2021-36886 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.6.1 Cross-Site Request Forgery (CSRF) Medium 6.5 < 1.2.6.1 1.2.6.1 2021-11-12 ✓ fixed in latest
CVE-2021-24144 Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.6 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') High 7.8 < 1.2.5.6 1.2.5.6 2021-01-25 ✓ fixed in latest
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.4 Unknown < 1.2.5.4 1.2.5.4 2021-01-21 ✓ fixed in latest
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.4 Unknown < 1.2.5.4 1.2.5.4 2021-01-19 ✓ fixed in latest
+ 4 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.3.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.3.2 1.3.2 0000-00-00 ✓ fixed in latest
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.5.4 Unknown < 1.2.5.4 1.2.5.4 ✓ fixed in latest
Contact Form 7 Database Addon < 1.2.5.4 - Authenticated SQL Injections Unknown < 1.2.5.4 1.2.5.4 ✓ fixed in latest
CVE-2025-6740 Contact Form 7 Database Addon < 1.3.2 - Unauthenticated Stored XSS via tmpD Parameter Unknown < 1.3.2 1.3.2 ✓ fixed in latest

How to fix it

Keep Contact Form Cfdb7 updated — 1.4.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.