CVE-2026-2599Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-05); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-05: 3Mentions · 2026-03-11: 1Mentions · 2026-03-23: 1Mentions · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-26: 1Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-05: 3Technical Details · 2026-03-23: 1Technical Details · 2026-03-26: 103-0503-1103-2303-26
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-053
Disclosure2General1
2026-03-111
Disclosure1
2026-03-231
Patch1
2026-03-261
Disclosure1
Full discourse6 posts
  • Ostorlab@OstorlabSec
    Disclosure

    🚨 CVE-2026-2599: Unauthenticated PHP Object Injection → WP_HTML_Token POP Chain A CVSS 9.8 Critical flaw in the Contact Form Entries WordPress plugin (≤ 1.4.7) enables full remote code execution with just two unauthenticated HTTP requests on WordPress 6.4.0‑6.4.1. This breakdown covers the exploitation chain via WP_HTML_Token and practical mitigation steps. 🔗 Full technical write-up: https://blog.ostorlab.co/cve-2026-2599-php-object-injection-wp-html-token.html

    Post summary

    The post announces a critical PHP Object Injection flaw in the Contact Form Entries plugin, provides a detailed exploitation chain, includes mitigation steps, and links to a comprehensive technical write-up.

    0101164
    574 followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2026-2599: CRITICAL] Vulnerable databases in WordPress plugins like Contact Form 7, WPforms, and Elementor identified with PHP Object Injection. Attackers may execute code if a POP chain is present.#cve,CVE-2026-2599,#cybersecurity https://cvefind.com/CVE-2026-2599

    Post summary

    The tweet announces CVE-2026-2599, a PHP Object Injection flaw in several WordPress plugins that could enable code execution via a POP chain, but it provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    0001053
    596 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical #WordPress Alert: CVE-2026-2599 https://nvd.nist.gov/vuln/detail/CVE-2026-2599 The Database for Contact Form 7, WPForms, Elementor Forms plugin for WordPress (<=1.4.7) is vulnerable to PHP Object Injection via untrusted deserialization. CVSS 9.8 Critical Update now and review plugins/themes for POP chains. #WordPress #CVE #CyberSecurity #SilentRisk #Malware

    Post summary

    A critical PHP Object Injection flaw (CVE‑2026‑2599) affects several popular WordPress form plugins; the post urges users to update immediately to mitigate the high‑severity vulnerability.

    0000036
    38 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en complemento de WordPress ❗ CVE-2026-2599 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-complemento-de-wordpress-8/ https://t.co/edxH1mMHDV

    Post summary

    The tweet announces the existence of CVE-2026-2599, a vulnerability in a WordPress plugin, and directs readers to an external source for additional details.

    00000109
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2599 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via des… https://www.cve.org/CVERecord?id=CVE-2026-2599

    Post summary

    The statement announces CVE‑2026‑2599, a PHP Object Injection flaw in WordPress form plugins up to v1.4.7, providing basic technical details but no evidence of exploitation or remediation.

    0000086
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2599 - Critical The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untr... https://www.thehackerwire.com/vulnerability/CVE-2026-2599/ https://t.co/skWuZDxklS

    Post summary

    CVE‑2026‑2599 exposes PHP Object Injection via deserialization in WordPress form plugins (Contact Form 7, WPforms, Elementor Forms) up to version 1.4.7, with critical severity announced but no exploit, patch, or active use reported.

    0000060
    124 followersView on X

Explore more