A vulnerability classified as problematic was found in Database for Contact Form 7 Plugin, Elementor Forms Plugin and WPforms Plugin up to 1.5.2 on WordPress. The affected element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-14870. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.