CSRF
CVE-2026-0811 is a medium-severity vulnerability (CVSS 5.4) affecting Advanced CF7 DB. The issue is classified as CSRF, part of the WordPress Plugin Ecosystem disclosure track on this site.
Authoritative sources and PoC material:
Detailed exploitation analysis, root-cause walkthrough, and remediation guidance for this finding live in the PoC repository. For broader methodology see services and research.
CVE-2026-0811 is a disclosed vulnerability (CSRF) in Advanced CF7 DB, coordinated through the standard CVE process by independent security researcher Kai Aizen.
You are affected if your environment runs an unpatched version of Advanced CF7 DB. Check the upstream advisory or NVD record for the precise affected version range, then verify against your deployed version.
Upgrade Advanced CF7 DB to the version that includes the upstream fix referenced in the NVD record. If an immediate upgrade is not possible, apply the mitigation guidance from the vendor advisory and restrict exposure of the affected surface area.
CVSS 5.4 · Medium. The vulnerability class is CSRF; consult the NVD and vendor advisory for vector details, exploitation prerequisites, and observed impact.
NVD record at https://nvd.nist.gov/vuln/detail/CVE-2026-0811, the MITRE CVE record at https://www.cve.org/CVERecord?id=CVE-2026-0811, and the vendor's security advisory page.