Executive brief
A vulnerability exists in the WP Insightly plugin for WordPress, which is used to integrate popular form builders with the Insightly CRM. An attacker can exploit this flaw to remotely take control of the website without needing any login credentials. This could lead to the theft of customer data, website defacement, or a total shutdown of the site's operations.
Technical details
The WP Insightly plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.1.4. This issue stems from the deserialization of untrusted data (CWE-502) provided by a user. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the server. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker can achieve remote code execution, perform SQL injection, or conduct arbitrary file deletion. The vulnerability is resolved in version 1.1.5.
Affected products
- WP Insightly WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4
Timeline
- 2025-05-17: disclosed: Reported by Frissi0n
- 2026-06-05: advisory: Patchstack advisory published
- 2026-06-15: advisory: NVD published CVE-2026-49085
- 2026-06-05: patched: Version 1.1.5 released