SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14870

HIGH · CVSS 7.1 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The vulnerability affects the Database for Contact Form 7, WPforms, and Elementor forms plugins for WordPress prior to version 1.5.3, allowing for reflected cross-site scripting due to inadequate sanitization of parameters on an admin page. This flaw poses a significant risk, particularly to high-privilege users like administrators, as it could be exploited to execute malicious scripts in their browsers. WordPress site administrators using these plugins should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-14870
Severity
HIGH
CVSS
7.1
EPSS
0.14%
WordPress

Original NVD Description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.