CVE-2025-67468: WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.4.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms cf7-salesforce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms: from n/a through <= 1.4.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67468?
CVE-2025-67468 is classified as a critical severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2025-67468?
To fix CVE-2025-67468, update the affected plugin 'Integration for Salesforce' to the latest version that addresses the missing authorization issue.
What plugins are affected by CVE-2025-67468?
CVE-2025-67468 affects the 'Integration for Salesforce' plugin and its integrations with 'Contact Form 7', 'WPForms', 'Elementor', 'Formidable', and 'Ninja Forms' .
What are the risks associated with CVE-2025-67468?
The risks associated with CVE-2025-67468 include potential data leakage and unauthorized manipulation of sensitive information.
Is my site vulnerable to CVE-2025-67468?
If you are using 'Integration for Salesforce' plugin version 1.4.6 or lower, your site is potentially vulnerable to CVE-2025-67468.