CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-7697: Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_...

9.8 CVSS

Description

The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.

Classification

CVE ID: CVE-2025-7697

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem Types

CWE-502 Deserialization of Untrusted Data

Affected Products

Vendor: crmperks

Product: Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.6% (probability of being exploited)

EPSS Percentile: 68.45% (scored less or equal to compared to others)

EPSS Date: 2025-07-19 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-7697
https://www.wordfence.com/threat-intel/vulnerabilities/id/a0146f17-35bd-45cf-b9c6-c4fce688efc2?source=cve
https://wordpress.org/plugins/integration-for-contact-form-7-and-google-sheets/#developers
https://plugins.trac.wordpress.org/browser/integration-for-contact-form-7-and-google-sheets/tags/1.1.1/integration-for-contact-form-7-and-google-sheets.php#L923
https://plugins.trac.wordpress.org/changeset/3329005/

Timeline