PHP Object Injection Vulnerability in Contact Form 7 Plugin by WordPress
CVE-2025-8145
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-8145?
The Contact Form 7 plugin for WordPress is susceptible to a PHP Object Injection vulnerability caused by the deserialization of untrusted input in the get_lead_fields function. This can enable unauthenticated attackers to inject arbitrary PHP objects, potentially leading to serious security issues. The vulnerability also encompasses a POP chain that allows attackers to delete arbitrary files and, under specific server configurations, may facilitate Remote Code Execution. It is crucial for website administrators using this plugin to apply updated versions to mitigate these risks.
Affected Version(s)
Redirection for Contact Form 7 * <= 3.2.4