CVE-2026-49106
CRM Perks · Integration for Contact Form 7 and Constant Contact
An unauthenticated PHP Object Injection vulnerability exists in the CRM Perks Integration for Contact Form 7 and Constant Contact, enabling potential remote code execution.
Executive summary
A critical unauthenticated PHP Object Injection vulnerability in the CRM Perks integration for Constant Contact poses a severe risk of remote system compromise.
Vulnerability
The vulnerability is an unauthenticated PHP Object Injection flaw. This allows remote attackers to supply malicious serialized data to the application, which is then insecurely deserialized, potentially leading to arbitrary code execution.
Business impact
A CVSS score of 9.8 underscores the critical nature of this vulnerability. An attacker can exploit this flaw to gain unauthorized access to the underlying server, potentially compromising sensitive business data and leading to a total loss of system integrity.
Remediation
Immediate Action: Update the Integration for Contact Form 7 and Constant Contact plugin to the latest version to address the vulnerability.
Proactive Monitoring: Perform regular audits of application logs to identify suspicious activity or unusual input patterns directed at the plugin.
Compensating Controls: Use a Web Application Firewall (WAF) to block requests containing serialized object patterns, providing a temporary shield until the official patch is applied.
Exploitation status
Public Exploit Available: False
Analyst recommendation
This vulnerability is highly critical and presents a significant security risk. Administrators must apply the latest plugin updates immediately to mitigate the threat of remote code execution.