Executive brief
A vulnerability exists in a WordPress plugin used to connect popular form builders like Contact Form 7 and Elementor with Salesforce. An attacker can exploit this flaw without needing a password to potentially take full control of the website, steal data, or disrupt services. This is a high-risk issue because it can be automated for mass attacks against any site using an outdated version of the plugin.
Technical details
The 'Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms' plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.4.3. This vulnerability occurs due to the deserialization of untrusted data (CWE-502) provided by an unauthenticated user. If a suitable Property-Oriented Programming (POP) chain is present on the server, a remote attacker can leverage this to execute arbitrary code, perform SQL injection, or achieve path traversal. The issue is resolved in version 1.4.4.
Affected products
- CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3
Timeline
- 2025-05-17: other: Vulnerability reported by researcher Frissi0n
- 2026-06-04: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: CVE published to NVD
- 2026-06-04: patched: Version 1.4.4 released to address the vulnerability