CVE-2025-7696CRITICAL 9.8EPSS p59.3%

CVE-2025-7696CVE-2025-7696

Description

The Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.3 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.03% probability of exploitation · percentile 59.3% · 2026-06-19T12:03:05Z
Published2025-07-19
Last modified2026-04-15

Underlying weaknesses· 1

CWE-502

References

  1. https://plugins.trac.wordpress.org/browser/integration-for-contact-form-7-and-pipedrive/tags/1.2.3/integration-for-contact-form-7-and-pipedrive.php#L953
  2. https://plugins.trac.wordpress.org/changeset/3329002/
  3. https://wordpress.org/plugins/integration-for-contact-form-7-and-pipedrive/#developers
  4. https://www.wordfence.com/threat-intel/vulnerabilities/id/6980112b-a555-47a4-b2d7-f0187d52fc63?source=cve

1

TypeTargetConfidenceTier
WeaknessDeserialization of Untrusted Datacwe-5020%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-7697
CVE
CVE-2025-7384
CVE
CVE-2026-2599
CVE
CVE-2025-8145
CVE
CVE-2025-6464
CVE
CVE-2025-4665
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.