Impact
The Advanced Contact form 7 DB plugin for WordPress suffers from an authorization bypass in all releases up to 2.1.3. The plugin fails to verify that a user has the proper privileges before allowing the import action, enabling attackers who have at least custom-level access to import forged CSV files as if they were legitimate form submissions. This can result in corrupted or malicious data being stored in form entries and potentially expose sensitive user input.
Affected Systems
This flaw affects the Advanced Contact form 7 DB plugin for WordPress versions 2.1.3 and earlier. The vendor is vsourz1td. The specific files involved include import_cf7_csv.php and import_cf7_entry.class.php within the plugin's admin area.
Risk and Exploitability
The flaw carries a CVSS score of 4.3, reflecting a moderate impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated, typically holding a role of custom or higher, to exploit the defect. Once authenticated, a user can trigger the import_cf7_id endpoint to inject arbitrary CSV data into any Contact Form 7 form managed by the plugin, potentially stifling system integrity and allowing attackers to overwrite legitimate records.
OpenCVE Enrichment