
Void Contact Form 7 Widget For Elementor Page Builder Security & Risk Analysis
wordpress.org/plugins/cf7-widget-elementorThis WordPress Plugin Adds Contact Form 7 widget element to Elementor page builder for easy drag & drop the created contact forms with CF7 (contac …
Is Void Contact Form 7 Widget For Elementor Page Builder Safe to Use in 2026?
Generally Safe
Score 89/100Void Contact Form 7 Widget For Elementor Page Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The "cf7-widget-elementor" plugin v2.4.2 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and generally implementing capability checks, there are significant concerns regarding its attack surface and output escaping.
The static analysis reveals one unprotected AJAX handler, which represents a direct entry point for unauthenticated attackers. The high percentage of unescaped output (60%) is particularly worrying, as it increases the likelihood of Cross-Site Scripting (XSS) vulnerabilities being exploitable, even if not explicitly detected in the limited taint analysis. The presence of the `unserialize` function, although not directly linked to a detected vulnerability in this analysis, is a known risk factor that requires careful handling of user-supplied data.
The vulnerability history shows a pattern of past issues including XSS, missing authorization, and CSRF, with the most recent in August 2024. While there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests potential recurring weaknesses in input validation and authorization logic. The plugin's strengths lie in its SQL handling and lack of raw SQL queries, but the identified unprotected entry point and prevalent output escaping issues, coupled with past vulnerability trends, necessitate a cautious approach.
Key Concerns
- Unprotected AJAX handler found
- High percentage of unescaped output
- Dangerous function 'unserialize' used
- Past vulnerabilities (XSS, Missing Auth, CSRF)
Void Contact Form 7 Widget For Elementor Page Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Void Contact Form 7 Widget For Elementor Page Builder <= 2.4.1 - Authenticated (Author+) Stored Cross-Site Scripting
Void Contact Form 7 Widget For Elementor Page Builder <= 2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via cf7_redirect_page Attribute
Void Contact Form 7 Widget For Elementor Page Builder <= 2.3 - Missing Authorization
Void Contact Form 7 Widget For Elementor Page Builder <= 2.1.1 - Cross-Site Request Forgery in void_cf7_opt_in_user_data_track
Void Contact Form 7 Widget For Elementor Page Builder Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Void Contact Form 7 Widget For Elementor Page Builder Attack Surface
AJAX Handlers 4
WordPress Hooks 18
Maintenance & Trust
Void Contact Form 7 Widget For Elementor Page Builder Maintenance & Trust
Maintenance Signals
Community Trust
Void Contact Form 7 Widget For Elementor Page Builder Alternatives
WI Contact Form 7 for Elementor
wi-contact-form-7-for-elementor
The WI Contact Form 7 for Elementor plugin allows you to easily add the Contact Form 7 widget element to pages being created with the Elementor page b …
Styler Mate for Contact Form 7
cf7-styler-for-divi
Style and enhance Contact Form 7 for Divi, Bricks, Elementor, Gutenberg, and more.
Mascaras CF7
mascaras-para-cf7
Adicione máscaras de telefone, CPF, CNPJ, CEP e Dinheiro nos campos do Contact Form 7, Elementor e outros tipos de formulários.
Eazy CF Captcha
eazy-cf-catpcha
Eazy C(omment)F(orm) Captcha adds a mathematic exercise to the comment form, contact form 7 & elementor, preventing bots to spam your comments and …
Cf7 For Elementor
cf7-for-elementor
This plugin is an addon of Elementor Page Builder. A simple and nice Contact Form 7 Widget for elementor.No need of going in cf7 & copying the sho …
Void Contact Form 7 Widget For Elementor Page Builder Developer Profile
2 plugins · 23K total installs
How We Detect Void Contact Form 7 Widget For Elementor Page Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-widget-elementor/custom-editor/assets/css/elementor-cf7-widget.css/wp-content/plugins/cf7-widget-elementor/custom-editor/assets/js/elementor-cf7-widget.js/wp-content/plugins/cf7-widget-elementor/custom-editor/assets/js/elementor-cf7-widget.jscf7-widget-elementor/custom-editor/assets/css/elementor-cf7-widget.css?ver=cf7-widget-elementor/custom-editor/assets/js/elementor-cf7-widget.js?ver=HTML / DOM Fingerprints
cf7-widget-promotion-noticecf7-widget-message-innercf7-widget-message-iconcf7-widget-notice-iconcf7-widget-message-contentcf7-widget-message-actioncf7-widget-buttoncf7-widget-remind-later+1 moredata-notice="void-cf7-promotion-notice-ele-query"data-nonce