CVE-2025-7697 Details
Description
The Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.1 via deserialization of untrusted input within the verify_field_val() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain in the Contact Form 7 plugin, which is likely to be used alongside, allows attackers to delete arbitrary files, leading to a denial of service or remote code execution when the wp-config.php file is deleted.
A PHP Object Injection vulnerability has been identified in the WordPress plugin 'Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms', affecting all versions through 1.1.1. The vulnerability arises from the deserialization of untrusted input in the 'verify_field_val()' function, allowing unauthenticated attackers to inject PHP objects. When used in conjunction with a property of the Contact Form 7 plugin, this could lead to the deletion of arbitrary files, causing a denial-of-service condition or, if the wp-config.php file is removed, potentially allowing remote code execution.
Users are advised to update the plugin to version 1.1.2 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 19, 2025CISA-ADP
Assessed Jul 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CRM Perks Integration for Google Sheets and Contact Form 7 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 19, 2025 | New CVE Received | [email protected] |
Volerion