Junglewise Threat Intelligence

CVE-2026-49106: Cool Plugins Integration for Contact Form 7 and Constant Contact PHP Object Injection

CVE-2026-49106 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Executive brief

A vulnerability exists in a WordPress plugin used to connect website contact forms with Constant Contact email marketing services. An attacker can exploit this flaw to gain full control over the website without needing any login credentials. This could lead to the theft of customer data, website defacement, or the installation of malicious software.

Technical details

The Integration for Contact Form 7 and Constant Contact plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.1.6. This issue stems from the insecure deserialization of user-supplied data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present in the environment, the attacker can achieve remote code execution, perform SQL injection, or access sensitive files. The vulnerability is resolved in version 1.1.7.

Affected products

  • Cool Plugins Integration for Contact Form 7 and Constant Contact <= 1.1.6

Timeline

  • 2025-05-17: other: Reported by researcher Frissi0n
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References