Skip to main content

Threat intelligence

Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter

CVE-2026-12094 · advanced-contact-form-7-compact-db

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Advanced Contact Form 7 Compact Db at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter
Affected software
advanced-contact-form-7-compact-db(Plugin)
Affected versions
  • ≤ 1.0.0
Authentication
Unauthenticated
Vulnerability type
Other
Published
23 June 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory 3fa5ddd8-8166-45eb-9576-8683c1d12cc6). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Advanced Contact Form 7 Compact Db version against this catalog when the Defence plugin is connected to your WordPress site.