Description
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a PHP Object Injection flaw located in the Editor component of the WordPress Ultimate Addons for Contact Form 7 plugin versions 3.5.51 and earlier. Attackers who can supply crafted serialized data may cause the plugin to instantiate arbitrary objects, potentially allowing execution of malicious code within the site’s context. This can result in compromise of the affected WordPress installation, data theft, or further spread of malware.

Affected Systems

The flaw affects the Themefic Ultimate Addons for Contact Form 7 plugin up to and including version 3.5.51. Any WordPress site that has not upgraded beyond this version is susceptible.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. Exploitation is possible through web-based interaction with the plugin’s Editor interface, meaning that a remote attacker can trigger the vulnerability by submitting malicious input. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but given the widespread use of WordPress plugins, the attack surface remains significant.

Generated by OpenCVE AI on September 30, 2026 at 16:11 UTC.

Remediation

Vendor Solution

Update the WordPress Ultimate Addons for Contact Form 7 plugin to the latest available version (at least 3.5.52).


OpenCVE Recommended Actions

  • Update the WordPress Ultimate Addons for Contact Form 7 plugin to the latest available version (3.5.52 or newer).
  • If an update cannot be applied immediately, disable the plugin or remove all instances of the contact form from the site to prevent exploitation.
  • Monitor web server logs and WordPress activity for any signs of object injection attempts or abnormal behavior.

Generated by OpenCVE AI on September 30, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
Title WordPress Ultimate Addons for Contact Form 7 plugin <= 3.5.51 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:13.430Z

Reserved: 2026-09-23T17:30:22.499Z

Link: CVE-2026-96833

cve-icon Vulnrichment

Updated: 2026-09-30T13:24:03.311Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:33.153

Modified: 2026-09-30T14:18:12.500

Link: CVE-2026-96833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:15:14Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data