The Elementor Contact Form DB plugin prior to 1.6 for WordPress allows CSRF via backend admin pages.
sean-barton elementor contact form db