What the vulnerability does
01Description
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.
Explanation of Vulnerability in Simple Terms
The CRM Perks integration plugin for Keap/Infusionsoft and contact form builders contains a deserialization vulnerability in versions up to 1.2.1. An attacker can send a specially crafted request over the network to deserialize untrusted data, leading to remote code execution on the affected WordPress site. No authentication or user interaction is required to exploit this vulnerability.
What an attacker can do
Run arbitrary PHP code on the site and take complete control of it.
Potential impact on your site
Complete site compromise: attacker can steal data, modify content, create admin accounts, or inject malware.
Conditions required to exploit
Network access only; no authentication or user action required.
Key dates
External resources
Related vulnerabilities