What the vulnerability does
01Description
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
Explanation of Vulnerability in Simple Terms
The Integration for Mailchimp and Contact Form 7 plugin processes untrusted data without proper validation, allowing an attacker to execute arbitrary PHP code on the site. No authentication or user interaction is required. All versions up to 1.1.8 are affected. Site administrators should update immediately to a patched version.
What an attacker can do
Run arbitrary PHP code on the site and take full control of it.
Potential impact on your site
Complete compromise of the WordPress site, including data theft, malware installation, and defacement.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities