CVE-2015-1874: Cfdbplugin Contact Form DB

Medium severity, CVSS 6.8. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plugin before 2.8.32 for WordPress allows remote attackers to hijack the authentication of administrators for requests that delete all plugin records via a request in the CF7DBPluginSubmissions page to wp-admin/admin.php.

Affected products

Published 2015-03-09. Last modified 2026-06-17.