PHP Object Injection Vulnerability in Contact Form 7 and Other WordPress Plugins
CVE-2025-7384

9.8CRITICAL

What is CVE-2025-7384?

The Contact Form 7, WPforms, and Elementor forms plugins for WordPress are susceptible to a PHP Object Injection vulnerability due to improper handling of deserialized input in the get_lead_detail function. This flaw allows unauthenticated attackers to manipulate PHP objects, exploiting an existing PHP Object Injection (POP) chain within the Contact Form 7 plugin. As a result, attackers can execute arbitrary commands, potentially leading to the deletion of critical files such as wp-config.php, which may cause denial of service or even remote code execution. It is crucial for users of these plugins to apply necessary updates and security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Database for Contact Form 7, WPforms, Elementor forms * <= 1.4.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.
CVE-2025-7384 : PHP Object Injection Vulnerability in Contact Form 7 and Other WordPress Plugins