Awesome Contact Form7 for Elementor Security & Risk Analysis

wordpress.org/plugins/awesome-contact-form7-for-elementor

Add Awesome Contact Form7 for Elementor with easy way.

7K active installs v3.2 PHP + WP 6.3+ Updated Dec 29, 2025
addonscontactcontact-formcontact-form-7elementor
99
A · Safe
CVEs total2
Unpatched0
Last CVEOct 15, 2024
Safety Verdict

Is Awesome Contact Form7 for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Awesome Contact Form7 for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Oct 15, 2024Updated 3mo ago
Risk Assessment

The "awesome-contact-form7-for-elementor" plugin v3.2 presents a mixed security posture. While the code exhibits good practices like 100% prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. Two AJAX handlers are present, and alarmingly, both lack authentication checks. This creates direct entry points for attackers to potentially exploit, especially when considering the taint analysis which revealed two flows with unsanitized paths, although they were not classified as critical or high severity.

The plugin's vulnerability history is also a point of concern. With two known medium-severity CVEs in the past, specifically related to Cross-Site Scripting, it indicates a pattern of past security weaknesses. Although currently there are no unpatched vulnerabilities, this history suggests a potential for recurring issues if past patterns are not adequately addressed. The lack of nonce checks on AJAX handlers, combined with the unsanitized taint flows and the history of XSS vulnerabilities, suggests that attackers could potentially inject malicious scripts or exploit functionalities through the unprotected AJAX endpoints.

In conclusion, the plugin shows strengths in its handling of database interactions and output sanitization. However, the presence of unprotected AJAX endpoints, indicated by the taint analysis, and the historical trend of XSS vulnerabilities are critical weaknesses that significantly increase the risk profile. The absence of nonce checks on these critical entry points amplifies these risks, making it imperative to address these unprotected pathways.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Medium severity CVEs in history
  • Missing nonce checks on AJAX
Vulnerabilities
2

Awesome Contact Form7 for Elementor Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2024-49319medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Awesome Contact Form7 for Elementor <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 15, 2024 Patched in 3.1 (4d)
CVE-2024-4486medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Awesome Contact Form7 for Elementor <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via AEP Contact Form 7 Widget

May 22, 2024 Patched in 3.0 (2d)
Code Analysis
Analyzed Mar 16, 2026

Awesome Contact Form7 for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
38 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped40 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
update_notice_status (includes\admin-notice\ca-framework\notice.php:227)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Awesome Contact Form7 for Elementor Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_update_notice_statusincludes\admin-notice\ca-framework\notice.php:67
authwp_ajax_aep_ac7_never_showincludes\aep-notice\admin-notice.php:45
WordPress Hooks 8
actionadmin_enqueue_scriptsincludes\admin-notice\ca-framework\notice.php:66
actionadmin_noticesincludes\admin-notice\ca-framework\notice.php:263
actionadmin_noticesincludes\admin-notice\ca-framework\require-control.php:92
actionadmin_noticesincludes\aep-notice\admin-notice.php:4
actionadmin_enqueue_scriptsincludes\aep-notice\admin-notice.php:33
actionelementor/preview/enqueue_stylesinit.php:18
actionwp_enqueue_scriptsinit.php:19
actionelementor/widgets/widgets_registeredinit.php:36
Maintenance & Trust

Awesome Contact Form7 for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 29, 2025
PHP min version
Downloads125K

Community Trust

Rating88/100
Number of ratings23
Active installs7K
Developer Profile

Awesome Contact Form7 for Elementor Developer Profile

B.M. Rafiul Alam

4 plugins · 7K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Contact Form7 for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awesome-contact-form7-for-elementor/assets/css/style.css/wp-content/plugins/awesome-contact-form7-for-elementor/includes/admin-notice/ca-framework/assets/css/ca-notification.css/wp-content/plugins/awesome-contact-form7-for-elementor/includes/admin-notice/ca-framework/assets/js/ajax-update.js
Script Paths
/wp-content/plugins/awesome-contact-form7-for-elementor/includes/admin-notice/ca-framework/assets/js/ajax-update.js
Version Parameters
awesome-contact-form7-for-elementor/assets/css/style.css?ver=awesome-contact-form7-for-elementor/includes/admin-notice/ca-framework/assets/css/ca-notification.css?ver=awesome-contact-form7-for-elementor/includes/admin-notice/ca-framework/assets/js/ajax-update.js?ver=

HTML / DOM Fingerprints

CSS Classes
ca-noticeca-successca-errorca-warningca-primary
Data Attributes
data-notice_iddata-notice_typedata-notice_styledata-notice_imgdata-notice_img_targetdata-notice_title+4 more
JS Globals
TB_Framework
FAQ

Frequently Asked Questions about Awesome Contact Form7 for Elementor