CVE-2026-6831: Advanced Contact form 7 DB <= 2.1.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure via 'acf7db' Shortcode
The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Contributor-level access and above, to read all Contact Form 7 submission data via the 'acf7db' shortcode.
Affected Software
Event History
Frequently Asked Questions
Which users can access the exposed submission data?
Any authenticated WordPress user with the Contributor role or a higher privilege level can exploit the issue. Anonymous visitors are not described as able to access the data.
What information can an attacker obtain?
An attacker can read all Contact Form 7 submission data through the acf7db shortcode. The available data does not further identify which submission fields or records may be present.
Which plugin versions are affected?
The description identifies all versions through 2.0.9 as affected. The supplied references include a change from version 2.1.1 to 2.1.2, but the provided data does not clearly reconcile that with the affected-version statement.