Description
The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Published: 2025-05-30
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Full Path Disclosure
Action: Immediate Patch
AI Analysis

Impact

The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plug‑in for WordPress allows unauthenticated users to retrieve the full file system path of the web application. This disclosure can assist attackers in mapping the environment and planning subsequent attacks, though the information itself is not actionable without another vulnerability. The weakness is categorized as CWE-200, where sensitive system information is exposed.

Affected Systems

All releases of the Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms by crmperks up to and including version 1.4.4 are affected. The plugin is distributed through the WordPress plugin repository and is installed on WordPress sites that use any of the supported form platforms.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1 percent shows a low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an unauthenticated attacker to access the plugin’s disclosure endpoint; further damage would depend on the presence of additional weaknesses on the target site.

Generated by OpenCVE AI on April 21, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plug‑in to the most recent release that removes the path disclosure flaw.
  • If an update cannot be applied immediately, disable or delete the plug‑in to stop the disclosure from occurring.
  • After applying the patch or disabling the plug‑in, perform a security scan to confirm that no sensitive paths are exposed.

Generated by OpenCVE AI on April 21, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-16458 The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
History

Fri, 30 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 May 2025 05:45:00 +0000

Type Values Removed Values Added
Description The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Title Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.4 - Unauthenticated Full Path Disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:14:09.172Z

Reserved: 2025-05-13T16:45:45.792Z

Link: CVE-2025-4659

cve-icon Vulnrichment

Updated: 2025-05-30T12:32:08.546Z

cve-icon NVD

Status : Deferred

Published: 2025-05-30T06:15:28.797

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-4659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T20:45:25Z

Weaknesses