SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14872

MEDIUM · CVSS 6.8 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-09-03

CyberRota Analysis

AI-Generated

The vulnerability affects the Database for Contact Form 7, WPforms, and Elementor forms plugins for WordPress prior to version 1.5.5, where insufficient sanitization of a parameter in SQL statements allows for SQL Injection attacks. This can be exploited by users with specific capabilities, which, while typically limited to administrators, can be assigned to lower-privileged roles. WordPress site administrators and developers should prioritize updating to the latest version to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14872
Severity
MEDIUM
CVSS
6.8
EPSS
0.22%
WordPress

Original NVD Description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.