CVE-2026-14870
HIGH NVDCVSS Score
7.1
Severity
HIGH
Source
NVD
Published
Jul 28, 2026
Description
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.