CVE-2026-3831Disclosure

LOWCVSS 4.3 · MEDIUM

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract all form submissions - including names, emails, phone numbers.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-01: 4PoC Mentioned / Linked · 2026-04-01: 1Technical Details · 2026-04-01: 204-01
Signal classification3 categories
Disclosure
250.0%
General
125.0%
PoC
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3831-contact-form-entries-version-1-4-9-medium-vulnerability-proof-of-concept CVE-2026-3831 #WordPress plugin #vulnerability contact-form-entries#cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post points to a proof‑of‑concept for CVE‑2026‑3831 on a WordPress plugin, confirming the existence of a vulnerability but lacking exploitation details or remediation guidance.

    0000054
    5 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3831 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3831 #CVE-2026-3831 #CVE #Medium #Wordpress #CyberSecurity #InfoSec https://t.co/GFYtut1N7Q

    Post summary

    The tweet merely announces the presence of CVE‑2026‑3831 with a severity score and link to NVD, offering no further technical or exploit details.

    0000035
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3831 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ent… https://www.cve.org/CVERecord?id=CVE-2026-3831

    Post summary

    The text announces a new vulnerability (CVE-2026-3831) affecting WordPress form plugins, noting unauthorized data access due to a missing capability check. No proof of concept, exploit, patch, or active exploitation details are included.

    00000117
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3831 - Database for Contact Form 7, WPforms, Elementor forms <= 1.4.9 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Shortcode Intel Report: https://ift.tt/vlFc3X7

    Post summary

    The alert details CVE-2026-3831 affecting certain WordPress form plugins via missing authorization, causing sensitive data exposure through shortcodes, with no mention of a PoC, exploit, or patch.

    0000042
    281 followersView on X

Explore more