
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0814 is a missing authorization vulnerability in the Advanced Contact form 7 DB plugin for WordPress that allows authenticated attackers with Subscriber-level access or above to export form submissions to an Excel file without proper authorization. It affects all plugin versions up to and including 2.0.9, and was disclosed on April 8, 2026. The CVE status is currently listed as "Deferred." It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Wordfence).
The root cause is a missing capability check (CWE-862) on the vsz_cf7_export_to_excel function within the plugin's admin class (class-advanced-cf7-db-admin.php, line 1507). Because no authorization check is enforced before executing the export function, any authenticated WordPress user — including those with the lowest default role (Subscriber) — can trigger the data export over the network without any user interaction. The vulnerable code is visible in the plugin's Trac repository at version 2.0.9, and the fix was introduced in changeset 3497481 (GitHub Advisory, WordPress Trac).
Successful exploitation results in unauthorized disclosure of sensitive data submitted through Contact Form 7 forms, which may include personally identifiable information (PII), contact details, or other confidential user-submitted content. The confidentiality impact is limited to data readable by the export function; there is no integrity or availability impact. The vulnerability does not enable remote code execution or lateral movement, but the exposed data could be leveraged for phishing, social engineering, or compliance violations (GitHub Advisory, Wordfence).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.025–0.032%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account on the target WordPress site, limiting opportunistic mass exploitation (GitHub Advisory, Wordfence).
vsz_cf7_export_to_excel function — typically via the WordPress admin AJAX endpoint or a direct admin URL — without possessing the required administrative capability.wp-admin/admin-ajax.php or wp-admin/admin.php) invoking the vsz_cf7_export_to_excel action from low-privileged user sessions..xlsx or Excel-format files generated in temporary or upload directories on the server.Update the Advanced Contact form 7 DB plugin to a version newer than 2.0.9, which includes the fix introduced in changeset 3497481. As an interim measure, site administrators should audit user roles and remove unnecessary Subscriber-level accounts, or restrict access to the WordPress admin area by IP if feasible. Reviewing form submission data for signs of unauthorized access is also recommended (WordPress Trac Changeset, Wordfence).
The vulnerability was reported by Wordfence and included in Sucuri's April 2026 vulnerability patch roundup, indicating routine coverage within the WordPress security community. No notable independent researcher commentary or significant social media discussion has been identified beyond standard advisory syndication (Sucuri Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."