CVE-2025-7697: Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 - Unauthenticated PHP Object Injection via verify_field_val Function
The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verifyfieldval() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7697?
CVE-2025-7697 is classified as a critical vulnerability due to the potential for remote code execution via PHP Object Injection.
How do I fix CVE-2025-7697?
To fix CVE-2025-7697, update the Integration for Google Sheets and Contact Form 7, WPForms, Elementor, or Ninja Forms plugin to version 1.1.2 or later.
Which versions are affected by CVE-2025-7697?
CVE-2025-7697 affects all versions of the Integration for Google Sheets, Contact Form 7, WPForms, Elementor, and Ninja Forms plugins up to and including version 1.1.1.
What kind of attack can CVE-2025-7697 enable?
CVE-2025-7697 can enable an attacker to execute arbitrary PHP code on the server due to the deserialization of untrusted input.
Is user input a factor in CVE-2025-7697?
Yes, CVE-2025-7697 involves PHP Object Injection through the deserialization of untrusted user input.