
Database Addon for Contact Form 7 – CFDB7 Security & Risk Analysis
wordpress.org/plugins/contact-form-cfdb7Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Is Database Addon for Contact Form 7 – CFDB7 Safe to Use in 2026?
Generally Safe
Score 90/100Database Addon for Contact Form 7 – CFDB7 has a strong security track record. Known vulnerabilities have been patched promptly.
The "contact-form-cfdb7" plugin version 1.3.5 presents a mixed security posture. While the static analysis indicates a seemingly small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication or permission checks, there are significant underlying concerns. The presence of the `unserialize` function, a known source of vulnerabilities, combined with a substantial number of SQL queries where only 27% utilize prepared statements, raises red flags regarding potential injection attacks. Furthermore, the output escaping is only properly implemented in 65% of cases, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities.
The plugin's vulnerability history is particularly concerning, with a total of 7 known CVEs, including 3 high-severity vulnerabilities. The types of past vulnerabilities—XSS, information exposure, CSV injection, CSRF, general injection, and SQL injection—paint a picture of an application that has historically struggled with input validation and output sanitization. While there are currently no unpatched CVEs, the recurring nature and severity of past issues suggest a propensity for exploitable flaws. The last vulnerability recorded in July 2025 indicates ongoing development or discovery of issues, though its recency might be an artifact of data reporting.
In conclusion, despite a minimal exposed attack surface in this specific version, the plugin's history of critical and high-severity vulnerabilities, coupled with the static analysis findings of dangerous functions like `unserialize` and inadequate prepared statement usage for SQL queries, points to a considerable risk. The less-than-ideal output escaping further exacerbates this risk. Users should exercise extreme caution and consider alternatives if possible.
Key Concerns
- Dangerous function 'unserialize' used
- Low percentage of SQL prepared statements
- Inadequate output escaping
- History of 3 high-severity CVEs
- History of 4 medium-severity CVEs
- Flow with unsanitized paths detected
Database Addon for Contact Form 7 – CFDB7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Contact Form 7 Database Addon <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting via tmpD Parameter
Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 - Unauthenticated Sensitive Information Exposure
Contact Form 7 Database Addon <= 1.2.6.3 - CSV Injection
Contact Form 7 Database Addon – CFDB7 plugin <= 1.2.5.9 - Cross-Site Request Forgery
Contact Form 7 Database Addon – CFDB7 <= 1.2.6.1 - Unauthenticated Stored Cross-Site Scripting
Contact Form 7 Database Addon <= 1.2.5.4 - CSV Injection
Contact Form 7 Database Addon <= 1.2.5.3 - SQL Injection
Database Addon for Contact Form 7 – CFDB7 Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Database Addon for Contact Form 7 – CFDB7 Attack Surface
WordPress Hooks 7
Maintenance & Trust
Database Addon for Contact Form 7 – CFDB7 Maintenance & Trust
Maintenance Signals
Community Trust
Database Addon for Contact Form 7 – CFDB7 Alternatives
Live Drag and Drop Builder for Contact Form 7
drag-and-drop-form-builder-for-contact-form-7
Use a nice Drag and Drop Form Builder when you Create forms with Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Contact Form 7: Accessible Defaults
contact-form-7-accessible-defaults
Replaces the default Contact Form 7 form with an accessible equivalent and provides a suite of selectable base forms.
Date Picker For Contact Form 7
date-picker-for-contact-form-7
Easily add a customizable Date Picker to Contact Form 7. Restrict dates, disable specific days, and improve your booking forms.
Database Addon for Contact Form 7 – CFDB7 Developer Profile
6 plugins · 621K total installs
How We Detect Database Addon for Contact Form 7 – CFDB7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-cfdb7/css/admin-style.cssHTML / DOM Fingerprints
wp-list-tablewidefatfixedstripedpagesuserscfdb7-main-pagewrap+1 moredata-cfdb7-action