PT-2026-51128 · Crm Perks · Database For Contact Form 7

Daroo

·

Published

2026-06-20

·

Updated

2026-06-20

·

CVE-2026-9843

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress versions prior to 1.5.2
Description Insufficient file path validation in the view page() function allows unauthenticated attackers to delete arbitrary files on the server. This occurs when an administrator views or edits a poisoned form entry, causing PHP's bracket parser to reshape an attacker-crafted JSON key. This process bypasses the stored-path isset check and triggers the deletion of a file specified via path traversal. Deleting critical files, such as wp-config.php, can lead to remote code execution.
Recommendations Update the plugin to a version later than 1.5.1.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9843

Affected Products

Database For Contact Form 7