Contact Form vCard Generator WordPress Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the Contact Form vCard Generator plugin for WordPress, in all versions through 2.4. The issue arises from a lack of proper capability checks in the 'wp_gvccf_check_download_request' function. This flaw allows unauthenticated attackers to access and export sensitive data from Contact Form 7 submissions, including names, phone numbers, email addresses, and messages. The data is extracted via the 'wp-gvc-cf-download-id' parameter.

Impact

Exploitation of this vulnerability leads to unauthorized access and exposure of sensitive information from Contact Form 7 submissions.

Reproduction

To reproduce this vulnerability, send a request to the WordPress site with the 'wp-gvc-cf-download-id' parameter set to a valid ID of a Contact Form 7 submission. Ensure that the 'wp-gvc-cf' parameter is also included, specifying the contact form from which data is to be downloaded. The absence of a capability check allows this request to be processed, resulting in the unauthorized export of submission data.

Added: Jan 9, 2026, 12:43 PM
Updated: Jan 9, 2026, 12:43 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
1.9
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.