Vulnerability in Database Addon For WPForms ( wpforms entries ) – WPFormsDB — CVE-2026-105260
MediumSeverity
0.1%Estimated exploit probability
20,000+ sitesInstalls
1.1.1Fixed in
What to do now
Update Database Addon For WPForms ( wpforms entries ) – WPFormsDB to 1.1.1 or later.
Affected versions
- Everything before 1.1.1
Affected: Database Addon For WPForms ( wpforms entries ) – WPFormsDB (plugin, database-for-wpforms)
What the vulnerability is
The Database Addon For WPForms ( wpforms entries ) – WPFormsDB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to 1.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.