WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database

Save Contact Form 7, Elementor, WPForms & Gravity Forms entries in database. View, filter, export form submissions to CSV & analytics reports.

6Reported vulnerabilities
7.2Highest CVSS score
1.5.3Latest version
10,000+Active installs

What to do now

Update Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database to 1.5.3 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 8, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2022-3764 High 7.2 1.0% 1.4.5 and earlier 1.4.6 November 8, 2022
CVE-2026-61947 High 7.2 0.3% 1.5.2 and earlier 1.5.3 July 16, 2026
CVE-2026-13378 High 7.2 0.4% 0 to 1.5.2 (inclusive) 1.5.3 July 11, 2026
CVE-2024-5325 Medium 6.5 0.5% Before 1.4.11 1.4.11 July 12, 2024
CVE-2024-5309 Medium 5.4 0.3% Before 1.4.13 1.4.13 September 5, 2024
CVE-2025-13409 Medium 4.9 0.3% 0 to 1.4.13 (inclusive) 1.5 January 6, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.