Impact
The vulnerable plugin performs a missing capability check in the entries_shortcode() function, allowing any authenticated user with Contributor level or higher to retrieve all form submissions, including names, email addresses, and phone numbers. The flaw exposes sensitive personally identifying information without any external code execution or denial of service impact. This weakness is classified as a missing authorization (CWE‑862).
Affected Systems
The issue affects the Database for Contact Form 7, WPforms, and Elementor forms plugin for WordPress, specifically all releases up to and including version 1.4.9. Sites using this plugin to capture contact form data are at risk, regardless of the overall WordPress installation version.
Risk and Exploitability
With a CVSS base score of 4.3, the vulnerability is considered medium severity. Exploitation requires only authenticated access at the Contributor role or higher, which is commonly granted on many sites. Because the attacker does not need to bypass additional authentication layers, the risk to user data is significant if the role is improperly assigned. The issue is not listed in CISA's KEV catalog and no EPSS score is available, but the straightforward exploitation path suggests a moderate likelihood of attack.
OpenCVE Enrichment