CVE-2026-49085
CRITICALWordPress WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-49085. PoCs published by izxci.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-49085, targeting an unsafe deserialization vulnerability in the WP Insightly plugin. The exploit automates detection, vulnerability checking, and payload injection via form endpoints.
Description
Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
Exploits (1)
This repository contains a functional Python exploit for CVE-2026-49085, targeting an unsafe deserialization vulnerability in the WP Insightly plugin. The exploit automates detection, vulnerability checking, and payload injection via form endpoints.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H