CVE-2021-36886: WordPress Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.5.9 - Cross-Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (versions <= 1.2.5.9).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-36886?
CVE-2021-36886 is a Cross-Site Request Forgery (CSRF) vulnerability discovered in the Contact Form 7 Database Addon - CFDB7 WordPress plugin (versions <= 1.2.5.9).
How severe is CVE-2021-36886?
CVE-2021-36886 has a severity rating of 8.8 (high).
What software is affected by CVE-2021-36886?
The Contact Form 7 Database Addon - CFDB7 WordPress plugin versions up to and including 1.2.5.9 are affected.
How can I fix CVE-2021-36886?
Update to version 1.2.6.1 or later of the Contact Form 7 Database Addon - CFDB7 WordPress plugin.
Where can I find more information about CVE-2021-36886?
You can find more information about CVE-2021-36886 at the following references: [Patchstack](https://patchstack.com/database/vulnerability/contact-form-cfdb7/wordpress-contact-form-7-database-addon-cfdb7-plugin-1-2-5-9-cross-site-request-forgery-csrf-vulnerability) and [WordPress Plugin Directory](https://wordpress.org/plugins/contact-form-cfdb7/#developers).