PHP Object Injection Vulnerability in Contact Form 7 Plugin by WordPress
CVE-2025-8145
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-8145?
The Contact Form 7 plugin for WordPress is susceptible to a PHP Object Injection vulnerability caused by the deserialization of untrusted input in the get_lead_fields function. This can enable unauthenticated attackers to inject arbitrary PHP objects, potentially leading to serious security issues. The vulnerability also encompasses a POP chain that allows attackers to delete arbitrary files and, under specific server configurations, may facilitate Remote Code Execution. It is crucial for website administrators using this plugin to apply updated versions to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Redirection for Contact Form 7 * <= 3.2.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved