Executive brief
A security vulnerability exists in a WordPress plugin used to integrate Zendesk with various popular form builders like Contact Form 7 and Elementor. This flaw allows an unauthenticated attacker to remotely inject malicious code into the website. If exploited, this could lead to a full site takeover, theft of customer data, or a complete service outage.
Technical details
The vulnerability is classified as a PHP Object Injection (CWE-502) occurring in the WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress. It stems from the deserialization of untrusted data provided by a user without proper validation. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker can achieve remote code execution, perform SQL injection, or access sensitive files via path traversal. The issue is resolved in version 1.1.5.
Affected products
- WP Zendesk WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4
Timeline
- 2025-05-17: other: Vulnerability reported by researcher Frissi0n
- 2026-06-05: patched: Version 1.1.5 released
- 2026-06-15: disclosed: NVD publication date