CVE-2025-7697 Information
Description
The Integration for Google Sheets and Contact Form 7 WPForms Elementor Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin which is likely to be used alongside allows attackers to delete arbitrary files leading to a denial of service or remote code execution when the wp-config.php file is deleted.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://plugins.trac.wordpress.org/browser/integration-for-contact-form-7-and-google-sheets/tags/1.1.1/integration-for-contact-form-7-and-google-sheets.php#L923 https://plugins.trac.wordpress.org/changeset/3329005/ https://wordpress.org/plugins/integration-for-contact-form-7-and-google-sheets/#developers https://www.wordfence.com/threat-intel/vulnerabilities/id/a0146f17-35bd-45cf-b9c6-c4fce688efc2?source=cve
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Related CNNVD
CNNVD-202507-2491 (Published: 2025-07-19)
Share on: