CVE-2026-49105
CRITICALWordPress WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin <= 1.1.4 - PHP Object Injection vulnerability
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-49105. PoCs published by izxci.
AI-analyzed exploit summary This repository contains a functional Python exploit for CVE-2026-49105, targeting a PHP object injection vulnerability in the WP Zendesk for Contact Form 7 plugin. The exploit automates detection, vulnerability checking, and payload injection via CF7 forms or direct POST requests.
Description
Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.
Exploits (1)
This repository contains a functional Python exploit for CVE-2026-49105, targeting a PHP object injection vulnerability in the WP Zendesk for Contact Form 7 plugin. The exploit automates detection, vulnerability checking, and payload injection via CF7 forms or direct POST requests.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H