CVE-2025-7384 is a critical PHP Object Injection vulnerability affecting all versions up to 1.4.3 of the "Database for Contact Form 7, WPforms, Elementor forms" WordPress plugin. This flaw allows unauthenticated attackers to inject PHP Objects through untrusted input deserialization in the get_lead_detail function. With a likely co-existing POP chain in the Contact Form 7 plugin, this can lead to arbitrary file deletion, causing denial of service or even remote code execution if critical files like wp-config.php are targeted. Rated 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the vulnerability has a high FAUCET Risk Score of 95/100, indicating severe potential impact. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not in CISA's KEV catalog, there are community discussions indicating awareness of this critical flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.4.3CPE match | cpe:2.3:a:crmperks:database_for_contact_form_7\,_wpforms\,_elementor_forms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.