PatchSiren

Advanced Contact form 7 DB CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Advanced Contact form 7 DB CVE published 2026-04-08

CVE-2026-0811

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 2.0.9. The vulnerability is caused by missing or incorrect nonce validation on the 'vsz_cf7_save_setting_callback' function. This allows unauthenticated attackers to delete form entries via a forged request, as long as they can trick a site administrator into perform [truncated]