External risk intelligence

WordPress CFDB7 SQL Injection to PHP Object Injection

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2025-4665

The vulnerability affects a WordPress plugin designed for contact forms. Contact forms are standard, public-facing components of websites, and the vulnerable endpoints are reachable via the internet as part of the normal operation of the web application.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability impacts a WordPress plugin, potentially allowing unauthenticated attackers to inject malicious code and execute arbitrary commands on affected systems. The issue stems from how the plugin handles user input, which can be exploited to bypass security measures and compromise the underlying server. Understanding the potential reach of this vulnerability is crucial for assessing organizational risk.

  • Flaw lets unauthenticated users inject malicious code.
  • Matters for websites using this common plugin.
  • Confirm relevance and exposure to understand risk.

Attack Path

How an attacker could exploit the issue

An attacker can initiate an attack by sending specially crafted input to a vulnerable WordPress plugin endpoint. This input manipulates backend database queries, leading to SQL injection and then insecure deserialization of PHP objects. This chain of events allows the attacker to inject arbitrary PHP objects into the system.

  • No authentication needed.
  • Crafted input to plugin endpoint.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could affect the integrity and availability of a WordPress site using the Contact Form CFDB7 plugin. When supported, attackers could craft specific inputs to manipulate database queries and trigger insecure deserialization, potentially leading to arbitrary code execution. This could compromise the website's backend operations and content.

  • Website backend integrity and availability.
  • Via crafted user input to specific endpoints.
  • Potential for arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given this pre-authentication SQL injection vulnerability in a WordPress plugin that cascades into insecure deserialization, the primary responsibility likely falls on the website owner or application owner to identify and manage remediation. The first practical step is to confirm whether the affected plugin is deployed on any public-facing or internal WordPress sites, determine its business criticality, and locate the accountable individual or team for its maintenance and security. Once identified, a risk-based remediation plan can be developed, potentially involving coordination with the vendor or implementing temporary controls if immediate patching is not feasible.

  • Own by website or application owner.
  • Verify plugin deployment and business criticality.
  • Plan remediation or mitigation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Contact Form CFDB7 plugin used for?

Contact Form CFDB7 is a WordPress plugin that collects and stores data submitted through website contact forms. It is commonly used by site administrators to manage visitor inquiries, feedback, or support requests directly within the WordPress dashboard, acting as a database for form submissions.

What does SQL injection to PHP object injection mean in CVE-2025-4665?

This refers to a two-stage attack. First, the plugin fails to sanitize user input, allowing an attacker to manipulate database queries (SQL Injection). This vulnerability then cascades, allowing the attacker to send malformed data that the system mistakenly processes as legitimate PHP objects (PHP Object Injection), potentially leading to arbitrary code execution.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted input to specific, reachable plugin endpoints. Crucially, the vulnerability does not trigger through standard, benign website interactions; it requires the malicious input to be sent directly to the vulnerable backend code to initiate the SQL and subsequent object injection.

Is my website at risk from this vulnerability?

Halo Surface Signal indicates that because this plugin manages public-facing contact forms, its vulnerable endpoints are typically reachable over the internet. If you use an affected version of the plugin, your site is likely exposed, as the attack does not require the attacker to have login credentials for your WordPress site.

What should I do if I use Contact Form CFDB7?

First, verify if your WordPress site has any version of Contact Form CFDB7 up to 1.3.2 installed. If you find it, assess the plugin's importance to your site's operations. Coordinate with your website maintenance team to prioritize updates or plan for temporary security measures if an official update is not immediately available.

References