Impact
The vulnerability is a PHP Object Injection flaw located in the Editor component of the WordPress Ultimate Addons for Contact Form 7 plugin versions 3.5.51 and earlier. Attackers who can supply crafted serialized data may cause the plugin to instantiate arbitrary objects, potentially allowing execution of malicious code within the site’s context. This can result in compromise of the affected WordPress installation, data theft, or further spread of malware.
Affected Systems
The flaw affects the Themefic Ultimate Addons for Contact Form 7 plugin up to and including version 3.5.51. Any WordPress site that has not upgraded beyond this version is susceptible.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. Exploitation is possible through web-based interaction with the plugin’s Editor interface, meaning that a remote attacker can trigger the vulnerability by submitting malicious input. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but given the widespread use of WordPress plugins, the attack surface remains significant.
OpenCVE Enrichment