CVE-2026-12081: Database for Contact Form 7, WPforms, Elementor forms < 1.5.2 - Unauthenticated PHP Object Injection via Entry File Field
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field value, allowing unauthenticated users to inject arbitrary PHP objects that are instantiated when an administrator views the stored entry. This is an incomplete fix of CVE-2025-7384 and CVE-2026-2599, whose deserialization paths were hardened while the entry-editor file-field path was missed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugins: Database for Contact Form 7, WPforms, Elementor formsto a version that resolves this vulnerability.Fixed in 1.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12081?
CVE-2026-12081 has a medium severity rating of 5.
What are the risks associated with CVE-2026-12081?
The risk associated with CVE-2026-12081 includes the potential for unauthenticated PHP object injection, which can lead to unauthorized code execution.
How do I fix CVE-2026-12081?
To fix CVE-2026-12081, update the Database for Contact Form 7, WPforms, Elementor forms plugin to version 1.5.2 or later.
Who is affected by CVE-2026-12081?
Users of the Database for Contact Form 7, WPforms, and Elementor forms WordPress plugin versions prior to 1.5.2 are affected by CVE-2026-12081.
What can attackers achieve with CVE-2026-12081?
Attackers can exploit CVE-2026-12081 to inject arbitrary PHP objects, which can execute malicious code when administratively accessed.