PHP Object Injection Vulnerability in Contact Form 7 Plugin by WordPress
CVE-2025-8145

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-8145?

The Contact Form 7 plugin for WordPress is susceptible to a PHP Object Injection vulnerability caused by the deserialization of untrusted input in the get_lead_fields function. This can enable unauthenticated attackers to inject arbitrary PHP objects, potentially leading to serious security issues. The vulnerability also encompasses a POP chain that allows attackers to delete arbitrary files and, under specific server configurations, may facilitate Remote Code Execution. It is crucial for website administrators using this plugin to apply updated versions to mitigate these risks.

Affected Version(s)

Redirection for Contact Form 7 * <= 3.2.4

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Tan Phat
.
CVE-2025-8145 : PHP Object Injection Vulnerability in Contact Form 7 Plugin by WordPress