PT-2026-79589 · WordPress · Ws Form Lite
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WS Form LITE – Drag & Drop Contact Form Builder versions prior to 1.10.81
Description
The plugin is susceptible to PHP Object Injection, a condition where untrusted input is deserialized, allowing an attacker to inject PHP objects. This occurs through the processing of form submission meta values. While the software itself does not contain a known POP chain (Property-Oriented Programming, a technique used to execute arbitrary code by leveraging existing classes in the application), the issue becomes critical if another installed plugin or theme provides one. In such cases, an unauthenticated attacker could potentially delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations
Update the plugin to a version newer than 1.10.80.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ws Form Lite