Executive brief
A security vulnerability exists in a WordPress plugin used to connect popular form builders like Contact Form 7 and Elementor with the Keap/Infusionsoft marketing platform. This flaw allows an unauthenticated attacker to remotely execute malicious commands on the website. If exploited, an attacker could gain full control of the site, steal customer data, or disrupt business operations.
Technical details
The 'Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms' plugin for WordPress is vulnerable to PHP Object Injection via the deserialization of untrusted data (CWE-502). This vulnerability can be exploited by a remote, unauthenticated attacker to inject a PHP object. If a suitable Property-Oriented Programming (POP) chain is present on the server, this can lead to remote code execution, SQL injection, or file system traversal. The issue is fixed in version 1.2.2.
Affected products
- Unknown Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1
Timeline
- 2025-05-17: other: Reported by researcher Frissi0n
- 2026-06-05: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published to NVD