κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / Critical WordPress Plugin Vulnerability Exposes 70,000+ Sites to RCE Attacks
άμυνα
.

Critical WordPress Plugin Vulnerability Exposes 70,000+ Sites to RCE Attacks

14/08/2025

A critical security vulnerability has been discovered in the popular “Database for Contact Form 7, WPforms, Elementor forms” WordPress plugin, potentially exposing over 70,000 websites to remote code execution attacks. 

The vulnerability, tracked as CVE-2025-7384 with a maximum CVSS score of 9.8, affects all versions up to and including 1.4.3 and was publicly disclosed on August 12, 2025.

The flaw stems from PHP Object Injection through deserialization of untrusted input in the plugin’s get_lead_detail function, allowing unauthenticated attackers to inject malicious PHP objects without requiring any user credentials or interaction. 

Key Takeaways
1. Critical WordPress plugin vulnerability exposes 70,000+ sites to remote code execution.
2. Attackers can exploit PHP Object Injection for system compromise.
3. Update immediately to prevent exploitation

This represents one of the most severe types of web application vulnerabilities, as it enables attackers to execute arbitrary code on vulnerable servers.

WordPress Plugin Deserialization Vulnerability

The vulnerability exploits deserialization of untrusted data, a common attack vector where malicious serialized objects are processed by the application without proper validation. 

Security researcher mikemyers identified the specific weakness in the plugin’s data handling mechanism, where user-supplied input is directly deserialized without sanitization checks.

What makes this vulnerability particularly dangerous is the presence of a Property-Oriented Programming (POP) chain in the Contact Form 7 plugin, which is commonly installed alongside the vulnerable database plugin. 

This POP chain allows attackers to escalate their initial object injection into arbitrary file deletion capabilities, potentially targeting critical system files like wp-config[.]php. 

When core WordPress configuration files are deleted, it can lead to complete system compromise or enable remote code execution scenarios.

The attack vector requires no authentication, making it extremely accessible to malicious actors. 

The CVSS vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates network-based attacks with low complexity, no privileges required, and high impact on confidentiality, integrity, and availability.

Risk FactorsDetailsAffected ProductsDatabase for Contact Form 7, WPforms, Elementor forms plugin ≤ 1.4.3ImpactRemote Code ExecutionExploit PrerequisitesNone (Unauthenticated attack)CVSS 3.1 Score9.8 (Critical)

Mitigations

Website administrators using the affected plugin should immediately update to version 1.4.4 or newer, which contains the necessary security patches. 

The vulnerability was addressed through proper input validation and sanitization mechanisms in the get_lead_detail function, preventing malicious object injection.

Given the critical nature of this vulnerability and its potential for widespread exploitation, security experts recommend implementing additional protective measures including Web Application Firewalls (WAF) and regular security monitoring.

Organizations should also conduct comprehensive security audits of their WordPress installations, particularly focusing on form-handling plugins that process user input.

The rapid disclosure and patching of this vulnerability highlight the importance of maintaining updated WordPress environments and the critical role of security researchers in identifying potentially devastating flaws before they can be exploited at scale.

Boost your SOC and help your team protect your business with free top-notch threat intelligence: Request TI Lookup Premium Trial.
Source: cybersecuritynews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-10

Haiku and SerenityOS aren’t daily drivers, but they’re the best weekend projects

Most people stick to Windows, macOS, or Linux because they get the job done with minimal hassle. They support a vast range of hardware, have robust ecosystems, and are built for day-to-day use. That doesn’t mean they’re the only operating systems worth trying. Away from the mainstream, projects like Haiku and SerenityOS demonstrate that there’s still plenty of room for alternative visions of how … [Read More...]

I clustered budget-friendly devices into a Proxmox HA lab, and it's more useful than I thought

Between its support for LXCs, community scripts, and simple management UI, Proxmox has a ton of features to make home labs more accessible to beginners and casual users. Unlike its rivals (especially ESXi), Proxmox requires minimal CPU, memory, and storage provisions. It also works right-out-of-the-box with most hardware, making it a terrific option for budget-friendly setups. However, despite its … [Read More...]

If you just need a laptop for the basics, this one at $349 is an absolute steal

This laptop is perfect for someone that's looking for something new on a budget. The Asus Vivobook 15 packs power with an Intel Core 5 processor, and also comes with a good amount of RAM and storage. But what makes it stand out right now is that steep discount from Walmart. For a limited time, you can score this laptop for $349, which is an absolute steal. Source: xda-developers.com … [Read More...]

The best Prime Day SSD deals: Save on gear from Samsung, Crucial, Seagate and others

If you've never considered adding a solid-state drive (SSD) to your PC or game console, October Prime Day is a great time to start — and if you already know what a difference extra storage can make, October Prime Day is the perfect time to outfit your build. For those who haven't heard of SSDs, they're physical upgrades that stack on top of a device's storage to make more files accessible at once. … [Read More...]

3 mistakes that ruined my first attempt at building a PC

Building your very first PC is never really easy, no matter how many tutorials you've watched on YouTube or parts you've memorized. In fact, it took me a couple of weeks just to properly research and source the parts for my first gaming rig back in 2012. By the time everything arrived, I thought the hard part was behind me. I knew that putting the parts together as a beginner would be … [Read More...]

The Reinforcement Gap — or why some AI skills improve faster than others  

AI coding tools are getting better fast. If you don’t work in code, it can be hard to notice how much things are changing, but GPT-5 and Gemini 2.5 have made a whole new set of developer tricks possible to automate, and last week Sonnet 2.4 did it again.   At the same time, other skills are progressing more slowly. If you are using AI to write emails, you’re probably getting the same … [Read More...]

The best Amazon Prime Day kitchen deals: Get up to 50 percent off our favorite air fryers and more

Whether you call it October Prime Day or use Amazon’s official title, Prime Big Deal days, the sale represents some of the lowest prices of the year in nearly every department — and that includes kitchen gear. We have a slew of food enthusiasts on staff who have tested plenty of excellent kitchen tech, as seen in our reviews and buying guides. We’ve covered everything from air fryers to sous vide … [Read More...]

Astronomers Spot Rapidly Growing Rogue Planet Feeding on Surrounding Gas

Astronomers have identified the fastest-growing planet ever observed, a free-floating world known as Cha 1107-7626. Located about 620 light-years from Earth, it is between five and ten times the mass of Jupiter. The rogue planet has been detected, and it has entered a sudden growth burst in recent months. It is swallowing down six billion tonnes of gas every second, making it the hungriest … [Read More...]

4 reasons why installing HACS was the best decision for my Home Assistant instance

While the Home Assistant Community Store (HACS) is considered by some people to be one of the best tools you can use with Home Assistant, I only stumbled upon it a while after setting up my own server. I'm still very early in my Home Assistant journey, but as I've gotten to know the platform better, I've realized that installing HACS was the best decision for my instance. Source: … [Read More...]

The Young Minds App wants to protect and educate children online and will show its tech at TechCrunch Disrupt 2025

An app called Young Minds wants to give parents control over what their kids do on the internet, while also protecting their children’s privacy and teaching them good online habits.  The startup was founded by Nino Dvalidze (pictured), an entrepreneur and a mother of two from the United Kingdom. Dvalidze told TechCrunch that the idea for Young Minds came from conversations with fellow … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • Haiku and SerenityOS aren’t daily drivers, but they’re the best weekend projects
  • I clustered budget-friendly devices into a Proxmox HA lab, and it's more useful than I thought
  • If you just need a laptop for the basics, this one at $349 is an absolute steal
  • The best Prime Day SSD deals: Save on gear from Samsung, Crucial, Seagate and others
  • 3 mistakes that ruined my first attempt at building a PC

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023