CVE-2025-4659: Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.4 - Unauthenticated Full Path Disclosure
The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4659?
CVE-2025-4659 has a high severity rating due to its potential to allow unauthorized attackers to access sensitive file paths.
How do I fix CVE-2025-4659?
To fix CVE-2025-4659, you should update the affected plugins to versions beyond 1.4.4.
Who is affected by CVE-2025-4659?
CVE-2025-4659 affects users of the Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, and Ninja Forms plugins up to version 1.4.4.
What type of vulnerability is CVE-2025-4659?
CVE-2025-4659 is classified as a Full Path Disclosure vulnerability.
Can CVE-2025-4659 be exploited by authenticated users?
CVE-2025-4659 can be exploited by unauthenticated users, making it especially severe.