What is CVE-2026-14872?
CVE-2026-14872 is an SQL Injection vulnerability found in the 'Database for Contact Form 7, WPforms, Elementor forms' WordPress plugin before version 1.5.5. It occurs due to improper sanitisation and escaping of a parameter used in an SQL statement, but is exploitable only by users with a specific capability, which is limited to administrators by default. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-14872 ‘Contact Form 7, WPforms, Elementor formaları üçün Database’ WordPress plaginin 1.5.5-dən əvvəlki versiyalarında aşkar edilmiş SQL Injection zəifliyidir. Zəiflik müəyyən parametrin düzgün təmizlənməməsi səbəbindən yaranır, lakin yalnız administrator səlahiyyətlərinə malik istifadəçilər tərəfindən istismar edilə bilər. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which user roles can exploit the CVE-2026-14872 vulnerability to gain protection?
This SQL Injection vulnerability can only be exploited by users with administrator privileges, as the required capability is restricted to administrators by default.
Which version of the 'Database for Contact Form 7, WPforms, Elementor forms' plugin is needed to protect against CVE-2026-14872?
To protect against this vulnerability, you need to update the plugin to version 1.5.5 or later, as the vulnerability exists in versions before 1.5.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.