
🚨 CVE-2025-7384: Database for Contact Form 7, WPfo... Unauthenticated PHP object injection chained with CF7's POP gadgets = instant wp-config.php deletion and RCE on 100K+ Wo... https://zerodaysignal.com/vulnerability/CVE-2025-7384 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post alerts users that CVE‑2025‑7384, a PHP object injection flaw in Contact Form 7, is enabling unauthenticated attackers to delete wp‑config.php files and execute arbitrary code, reportedly impacting more than 100,000 WordPress sites.
