CVE-2026-0814
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0814 is a missing authorization vulnerability in the Advanced Contact form 7 DB plugin for WordPress that allows authenticated attackers with Subscriber-level access or above to export form submissions to an Excel file without proper authorization. It affects all plugin versions up to and including 2.0.9, and was disclosed on April 8, 2026. The CVE status is currently listed as "Deferred." It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Wordfence).

Technical details

The root cause is a missing capability check (CWE-862) on the vsz_cf7_export_to_excel function within the plugin's admin class (class-advanced-cf7-db-admin.php, line 1507). Because no authorization check is enforced before executing the export function, any authenticated WordPress user — including those with the lowest default role (Subscriber) — can trigger the data export over the network without any user interaction. The vulnerable code is visible in the plugin's Trac repository at version 2.0.9, and the fix was introduced in changeset 3497481 (GitHub Advisory, WordPress Trac).

Impact

Successful exploitation results in unauthorized disclosure of sensitive data submitted through Contact Form 7 forms, which may include personally identifiable information (PII), contact details, or other confidential user-submitted content. The confidentiality impact is limited to data readable by the export function; there is no integrity or availability impact. The vulnerability does not enable remote code execution or lateral movement, but the exposed data could be leveraged for phishing, social engineering, or compliance violations (GitHub Advisory, Wordfence).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.025–0.032%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid authenticated account on the target WordPress site, limiting opportunistic mass exploitation (GitHub Advisory, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Advanced Contact form 7 DB plugin (version ≤ 2.0.9) by checking plugin metadata or using tools like WPScan.
  2. Obtain authenticated access: Register or log in as a Subscriber-level (or higher) user on the target WordPress site.
  3. Trigger the export function: Send an authenticated HTTP request to invoke the vsz_cf7_export_to_excel function — typically via the WordPress admin AJAX endpoint or a direct admin URL — without possessing the required administrative capability.
  4. Retrieve exported data: Download the resulting Excel file containing all form submissions, which may include names, email addresses, phone numbers, and other user-submitted data (GitHub Advisory, WordPress Trac).

Indicators of compromise

  • Network: Unexpected HTTP requests to WordPress admin endpoints (e.g., wp-admin/admin-ajax.php or wp-admin/admin.php) invoking the vsz_cf7_export_to_excel action from low-privileged user sessions.
  • Logs: WordPress access logs showing Subscriber-level authenticated users accessing export-related admin URLs or AJAX actions; repeated export requests from the same user account in a short timeframe.
  • File System: Unexpected .xlsx or Excel-format files generated in temporary or upload directories on the server.

Mitigation and workarounds

Update the Advanced Contact form 7 DB plugin to a version newer than 2.0.9, which includes the fix introduced in changeset 3497481. As an interim measure, site administrators should audit user roles and remove unnecessary Subscriber-level accounts, or restrict access to the WordPress admin area by IP if feasible. Reviewing form submission data for signs of unauthorized access is also recommended (WordPress Trac Changeset, Wordfence).

Community reactions

The vulnerability was reported by Wordfence and included in Sucuri's April 2026 vulnerability patch roundup, indicating routine coverage within the WordPress security community. No notable independent researcher commentary or significant social media discussion has been identified beyond standard advisory syndication (Sucuri Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-82923CRITICAL9.8
  • gw-website-builder-main
NoNoSep 04, 2026
CVE-2026-12483HIGH7.5
  • sfwd-lms
NoYesSep 04, 2026
CVE-2026-84045MEDIUM5.3
  • ecab-taxi-booking-manager
NoYesSep 04, 2026
CVE-2026-84044MEDIUM5.3
  • mp-restaurant-menu
NoYesSep 04, 2026
CVE-2026-84043MEDIUM5.3
  • epayco-gateway
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management