Authorization Flaw in Advanced Contact Form 7 DB Plugin for WordPress
CVE-2026-6831
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 September 2026
What is CVE-2026-6831?
The Advanced Contact Form 7 DB plugin for WordPress contains a significant security weakness whereby it fails to adequately verify user authorization for specific actions. This loophole impacts all versions up to and including 2.0.9. As a result, authenticated users with Contributor level access or higher may exploit this vulnerability to gain unauthorized access to all Contact Form 7 submission data through the 'acf7db' shortcode. It is crucial for users and administrators to update to the latest version to mitigate potential data exposure risks.
Affected Version(s)
Advanced Contact form 7 DB 0 <= 2.1.1