CVE-2026-14870: Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14870?
CVE-2026-14870 has a risk score of 40, indicating a medium severity level due to potential exploitation risks.
How do I fix CVE-2026-14870?
To fix CVE-2026-14870, update the Database for Contact Form 7, WPforms, Elementor forms plugin to version 1.5.3 or later.
Who is affected by CVE-2026-14870?
CVE-2026-14870 affects users of the Database for Contact Form 7, WPforms, and Elementor forms plugin on WordPress sites prior to version 1.5.3.
What kind of vulnerability is CVE-2026-14870?
CVE-2026-14870 is a Reflected Cross-Site Scripting (XSS) vulnerability.
What can attackers do with CVE-2026-14870?
Attackers can exploit CVE-2026-14870 to execute malicious scripts in the context of high privilege users, including admins, on affected WordPress sites.