Description
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy() without validating that the value corresponds to a legitimately uploaded file — when no file is present in $_FILES, raw_value reflects the attacker-controlled POST string. copy() accepts both local filesystem paths and URL sources, so the attacker can target any file readable by the PHP process or supply an attacker-controlled remote URL. Elementor Pro is a prerequisite for triggering the code path (it owns the elementor_pro/forms/new_record hook and populates the Form_Record object), but the bug itself is entirely in Contact Form Entries' handler. This could allow unauthenticated attackers to disclose arbitrary files on the affected site's server. The file is copied to a directory unknown to the attacker; the hashed directory name provides defense-in-depth but is generated from non-cryptographic sources (uniqid() + rand()) and should not be relied upon as the primary mitigation.
Published: 2026-07-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The plugin’s create_entry_el() routine reads the raw_value from an Elementor Pro upload field and passes it straight to PHP’s copy() without validating that the value corresponds to a legit uploaded file. When no file is present, raw_value can be set by an unauthenticated attacker in a crafted POST request; copy() accepts both local paths and URLs, allowing the attacker to read any file readable by the PHP process or to copy data from an arbitrary remote location into a hashed directory that is not reliably protected.

Affected Systems

WordPress sites that run the crmperks Database for Contact Form 7, WPforms, Elementor Forms plugin version 1.5.1 or earlier and have Elementor Pro installed. The vulnerable code path is triggered by Elementor Pro, but the flaw resides in Contact Form Entries; updating the plugin beyond 1.5.1 removes the exposed path, while sites without Elementor Pro or using newer plugin versions are not affected.

Risk and Exploitability

With a CVSS score of 6.5 the vulnerability is moderate, and its EPSS score of less than 1 % indicates a low probability of exploitation in the wild at present; it is not listed in the CISA KEV catalog. An attacker can craft an unauthenticated POST request to the Elementor Pro form upload endpoint, injecting a raw_value that points to a server file or a remote URL. Because PHP’s copy() does not enforce validation, the attacker can disclose any file that the PHP process can read or copy arbitrary external data into the site.

Generated by OpenCVE AI on July 22, 2026 at 13:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Database for Contact Form 7, WPforms, Elementor Forms plugin to a version newer than 1.5.1 to eliminate the vulnerable code path.
  • If an immediate upgrade is not possible, disable or remove upload‑type fields in Elementor Pro forms to prevent the create_entry_el() routine from being executed.
  • Restrict the PHP process’s file‑read permissions and apply web‑server configuration rules to block access to sensitive directories, thereby limiting the impact of any copy operation.

Generated by OpenCVE AI on July 22, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Crmperks
Crmperks database For Contact Form 7, Wpforms, Elementor Forms
Wordpress
Wordpress wordpress
Vendors & Products Crmperks
Crmperks database For Contact Form 7, Wpforms, Elementor Forms
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy() without validating that the value corresponds to a legitimately uploaded file — when no file is present in $_FILES, raw_value reflects the attacker-controlled POST string. copy() accepts both local filesystem paths and URL sources, so the attacker can target any file readable by the PHP process or supply an attacker-controlled remote URL. Elementor Pro is a prerequisite for triggering the code path (it owns the elementor_pro/forms/new_record hook and populates the Form_Record object), but the bug itself is entirely in Contact Form Entries' handler. This could allow unauthenticated attackers to disclose arbitrary files on the affected site's server. The file is copied to a directory unknown to the attacker; the hashed directory name provides defense-in-depth but is generated from non-cryptographic sources (uniqid() + rand()) and should not be relied upon as the primary mitigation.
Title Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Crmperks Database For Contact Form 7, Wpforms, Elementor Forms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-02T15:54:04.136Z

Reserved: 2026-05-20T20:03:22.747Z

Link: CVE-2026-9145

cve-icon Vulnrichment

Updated: 2026-07-02T13:56:51.034Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')