AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-14872

UNKNOWN · CVSS N/A EPSS 0.16% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The vulnerability affects the Database for Contact Form 7, WPforms, and Elementor forms plugins for WordPress prior to version 1.5.5, where insufficient sanitization of a parameter in SQL statements allows for SQL Injection attacks. This can be exploited by users with specific capabilities, which, while typically limited to administrators, can be assigned to lower-privileged roles. WordPress site administrators and developers should prioritize updating to the latest version to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14872
Severity
UNKNOWN
CVSS
N/A
EPSS
0.16%
WordPress

Original NVD Description

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated to lower privileged roles.