CVE-2026-12081: Unknown Database For Contact Form 7, Wpforms, Elementor Forms

Medium severity, CVSS 5.0. EPSS: 0.2% chance of exploitation in the next 30 days.

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry. This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.

Affected products

  • Unknown Database For Contact Form 7, Wpforms, Elementor Forms: before 1.5.2 (fixed in 1.5.2)

Published 2026-07-13. Last modified 2026-07-13.