CVE-2026-49106

CRM Perks · Integration for Contact Form 7 and Constant Contact

An unauthenticated PHP Object Injection vulnerability exists in the CRM Perks Integration for Contact Form 7 and Constant Contact, enabling potential remote code execution.

Executive summary

A critical unauthenticated PHP Object Injection vulnerability in the CRM Perks integration for Constant Contact poses a severe risk of remote system compromise.

Vulnerability

The vulnerability is an unauthenticated PHP Object Injection flaw. This allows remote attackers to supply malicious serialized data to the application, which is then insecurely deserialized, potentially leading to arbitrary code execution.

Business impact

A CVSS score of 9.8 underscores the critical nature of this vulnerability. An attacker can exploit this flaw to gain unauthorized access to the underlying server, potentially compromising sensitive business data and leading to a total loss of system integrity.

Remediation

Immediate Action: Update the Integration for Contact Form 7 and Constant Contact plugin to the latest version to address the vulnerability.

Proactive Monitoring: Perform regular audits of application logs to identify suspicious activity or unusual input patterns directed at the plugin.

Compensating Controls: Use a Web Application Firewall (WAF) to block requests containing serialized object patterns, providing a temporary shield until the official patch is applied.

Exploitation status

Public Exploit Available: False

Analyst recommendation

This vulnerability is highly critical and presents a significant security risk. Administrators must apply the latest plugin updates immediately to mitigate the threat of remote code execution.