Description
WordPress Plugin Save Contact Form 7 is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Save Contact Form 7 version 2.0 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that only users with the "manage_options" capability can view submissions or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Form Lightbox Security Bypass (2.1)
WordPress Plugin Responsive Lightbox2 Cross-Site Scripting (1.0.2)
WordPress Plugin Advanced Custom Fields PRO Multiple Security Bypass Vulnerabilities (5.10)
WordPress Plugin Best Image Gallery & Responsive Photo Gallery-FooGallery Security Bypass (1.6.15)