The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
History

Sun, 02 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Crmperks
Crmperks database For Contact Form 7, Wpforms, Elementor Forms
Wordpress
Wordpress wordpress
Vendors & Products Crmperks
Crmperks database For Contact Form 7, Wpforms, Elementor Forms
Wordpress
Wordpress wordpress

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Title Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-07-28T06:00:02.324Z

Updated: 2026-07-28T13:19:17.540Z

Reserved: 2026-07-06T14:11:37.540Z

Link: CVE-2026-14870

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.