Junglewise Threat Intelligence

CVE-2026-12081: Database for Contact Form 7 PHP object injection in entry editor

CVE-2026-12081 · Severity: info · CVSS 5 · Published 2026-07-13

Vendors: Unknown.

Executive brief

A WordPress plugin used to store and manage contact form submissions is vulnerable to a security flaw that allows unauthorized visitors to plant malicious data. When a site administrator later views or saves these submissions in the management dashboard, the malicious data is automatically processed, potentially allowing the attacker to execute unauthorized code or delete files. This could lead to a full site takeover if the attacker uses a sophisticated exploit chain.

Technical details

The vulnerability is a PHP Object Injection (CWE-502) resulting from an incomplete fix for previous deserialization issues (CVE-2025-7384 and CVE-2026-2599). The plugin fails to restrict allowed classes when calling maybe_unserialize() on form-field values within the entry-editor file-field path. An unauthenticated attacker can submit a contact form where a file-upload field is replaced with a text parameter containing a serialized PHP object. The object is stored in the database and subsequently instantiated when an administrator interacts with the 'CRM Entries' screen and saves the entry. If a suitable POP chain is present in the environment (via other plugins or themes), this can lead to arbitrary file deletion or remote code execution. The issue is fixed in version 1.5.2.

Affected products

  • Unknown Database for Contact Form 7, WPforms, Elementor forms (contact-form-entries) < 1.5.2

Timeline

  • 2026-04-20: disclosed: Initial discovery/publication date mentioned in references
  • 2026-06-22: advisory: WPScan advisory published
  • 2026-07-13: advisory: NVD publication date

References

Related threats