PT-2026-22464 · Unknown+1 · Contact Form 7+1

Quốc Huy

·

Published

2026-02-28

·

Updated

2026-03-05

·

CVE-2026-2471

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Mail Logging versions prior to 1.15.1
Description The WP Mail Logging plugin for WordPress is susceptible to PHP Object Injection in versions up to and including 1.15.0. This occurs due to the deserialization of untrusted input from the email log message field. The BaseModel class constructor uses maybe unserialize() on database properties without proper validation, allowing attackers to inject a PHP Object through a double-serialized payload. This payload can be submitted through any public-facing form that sends email, such as Contact Form 7. When an administrator views the logged email, the malicious payload is deserialized. The impact of this issue is limited unless another plugin or theme containing a PHP Object Payload (POP) chain is installed, which could allow actions like file deletion, data retrieval, or code execution.
Recommendations Update WP Mail Logging to version 1.15.1 or later.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-2471

Affected Products

Contact Form 7
Wp Mail Logging