Description
Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.5.0.
Published: 2025-12-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a deserialization of untrusted data that permits object injection. An attacker can supply crafted serialized payloads that the PDF for Contact Form 7 plugin processes, potentially allowing remote code execution or arbitrary data manipulation. The weakness corresponds to CWE-502, indicating that the application fails to validate or sanitize deserialized input properly. The impact is high, as a successful exploitation could compromise the entire WordPress installation, yield full control, and enable further lateral movement.

Affected Systems

The affected product is the add‑ons.org PDF for Contact Form 7 plugin, specifically all releases from the first available version up to and including 6.5.0. Users employing any of these versions are vulnerable unless the plugin has been upgraded beyond 6.5.0. No other vendors or products are mentioned.

Risk and Exploitability

The CVSS score of 8.8 classifies this as a high‑severity flaw, yet the EPSS score of less than 1% indicates that the likelihood of an actual exploit in the wild is very low at this time. The CVE is not listed in the CISA KEV catalog. The likely attack vector is remote, via the web, where an attacker submits a malicious payload through the plugin’s form handling or its endpoints. Successful exploitation would require the plugin to be active and the WordPress site exposed to the internet. No public exploits are known, but the high severity suggests that defenders should treat it as a high‑risk threat.

Generated by OpenCVE AI on April 29, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PDF for Contact Form 7 plugin to a version newer than 6.5.0.
  • If an upgrade is not immediately possible, restrict access to the contact forms by limiting user roles or disabling the plugin until a patch is applied.
  • Implement strict input validation on any data sent to the plugin, ensuring that serialized data is not accepted from untrusted sources.

Generated by OpenCVE AI on April 29, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.3.4. Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.5.0.
Title WordPress PDF for Contact Form 7 plugin <= 6.3.4 - Deserialization of untrusted data vulnerability WordPress PDF for Contact Form 7 plugin <= 6.5.0 - Deserialization of untrusted data vulnerability

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Object Injection.This issue affects PDF for Contact Form 7: from n/a through <= 6.3.4.
Title WordPress PDF for Contact Form 7 plugin <= 6.3.4 - Deserialization of untrusted data vulnerability
Weaknesses CWE-502
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:37:04.220Z

Reserved: 2025-09-25T15:20:02.781Z

Link: CVE-2025-60081

cve-icon Vulnrichment

Updated: 2025-12-18T16:44:33.270Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:08.300

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-60081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T13:15:11Z

Weaknesses