WP Security CheckVulnerability data as of October 10, 2026

Vulnerability alerts / October 8, 2026

Vulnerability in Database Addon For WPForms ( wpforms entries ) – WPFormsDB — CVE-2026-105260

MediumSeverity
CVSS 4.3
0.1%Estimated exploit probability
EPSS
20,000+ sitesInstalls
1.1.1Fixed in

What to do now

Update Database Addon For WPForms ( wpforms entries ) – WPFormsDB to 1.1.1 or later.

Affected versions

  • Everything before 1.1.1

Affected: Database Addon For WPForms ( wpforms entries ) – WPFormsDB (plugin, database-for-wpforms)

Check: The plugin on wordpress.org / Our record for Database Addon For WPForms ( wpforms entries ) – WPFormsDB

What the vulnerability is

The Database Addon For WPForms ( wpforms entries ) – WPFormsDB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

This description is reproduced verbatim from the public vulnerability record.

Sources

Part of this record comes from Wordfence Intelligence. Original: https://www.wordfence.com/threat-intel/vulnerabilities/id/51103e02-f487-4ee3-a090-6670d4688381
Copyright 2012-2026 Defiant Inc. / Full license text

This page is compiled automatically from public databases. Accuracy is not guaranteed; confirm against the vendor advisory before acting.

See other alerts