Impact
The PDF for WPForms plugin is vulnerable to deserialization of untrusted data, enabling object injection. This weakness, identified as CWE‑502, allows an attacker to craft malicious serialized objects that the plugin will unserialize without proper validation. The result can be arbitrary code execution or other unauthorized actions on the server where WordPress is running.
Affected Systems
Affected vendors and products are add‑ons.org PDF for WPForms. All releases from the earliest available version up through 6.5.0 include this flaw. Any WordPress site that has any of these plugin versions installed is potentially vulnerable.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. The EPSS score is less than 1%, suggesting a very low current probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Likely attack vectors involve user‑supplied form data or uploaded documents that the plugin processes, leading the plugin to unserialize the data. Although exploitation is not currently widespread, the capability to execute code remotely warrants urgent attention.
OpenCVE Enrichment