CVE-2025-7384Active Exploitation

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-08: 1Active Exploitation · 2026-04-08: 1Technical Details · 2026-04-08: 104-08
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Active Exploitation

    🚨 CVE-2025-7384: Database for Contact Form 7, WPfo... Unauthenticated PHP object injection chained with CF7's POP gadgets = instant wp-config.php deletion and RCE on 100K+ Wo... https://zerodaysignal.com/vulnerability/CVE-2025-7384 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post alerts users that CVE‑2025‑7384, a PHP object injection flaw in Contact Form 7, is enabling unauthenticated attackers to delete wp‑config.php files and execute arbitrary code, reportedly impacting more than 100,000 WordPress sites.

    00000302
    204 followersView on X

Explore more