Description
The Contact Form 7 Database Addon – CFDB7 plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.6.8 via the cfdb7_before_send_mail function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32438 | The Contact Form 7 Database Addon – CFDB7 plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.2.6.8 via the cfdb7_before_send_mail function. This can allow unauthenticated attackers to extract sensitive data, such as Personally Identifiable Information, from files uploaded by users. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 - Unauthenticated Sensitive Information Exposure | |
| Weaknesses | CWE-200 |
Thu, 26 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arshidkv12
Arshidkv12 contact Form Addon |
|
| CPEs | cpe:2.3:a:arshidkv12:contact_form_addon:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arshidkv12
Arshidkv12 contact Form Addon |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:10:50.912Z
Reserved: 2024-04-16T00:17:43.172Z
Link: CVE-2024-3870
Updated: 2024-08-01T20:26:57.223Z
Status : Awaiting Analysis
Published: 2024-05-02T17:15:31.743
Modified: 2026-04-08T18:21:35.037
Link: CVE-2024-3870
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD