Vsourz develops a narrow range of WordPress plugins including Advanced CF7 DB, All in One Redirection, and CF7 Invisible reCAPTCHA that extend form handling and security capabilities. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around web application input-handling and authorization weaknesses such as cross-site scripting, SQL injection, CSRF, and improper access control that are characteristic of plugin-based WordPress extensions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vsourz over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13571CRITICAL A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successful exploitation of this vulnerability would allow a remote at | Jul 29, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-24905HIGH The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the | Mar 21, 2022 | 8.0 | 26 | NO | NO |
CVE-2018-21012MEDIUM The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS. | Sep 9, 2019 | 6.1 | 22 | NO | NO |
CVE-2023-28167HIGH Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3 versions. | Nov 12, 2023 | 8.8 | 21 | NO | NO |
CVE-2023-2493HIGH The All In One Redirection WordPress plugin before 2.2.0 does not properly sanitise and escape multiple parameters before using them in an SQL statement, leading to a SQL injection | Jul 10, 2023 | 7.2 | 21 | NO | NO |
CVE-2022-45285MEDIUM Vsourz Digital Advanced Contact form 7 DB Versions 1.7.2 and 1.9.1 is vulnerable to Cross Site Scripting (XSS). | Feb 13, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-37245MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vsourz Digital All In One Redirection allows Reflected XSS.This issue a | Jul 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2022-29408MEDIUM Persistent Cross-Site Scripting (XSS) vulnerability in Vsourz Digital's Advanced Contact form 7 DB plugin <= 1.8.7 at WordPress. | May 25, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vsourz.
Media articles that mention a CVE ID that affects a product developed by Vsourz — matched by CVE ID, not by vendor name.