CVE-2025-60084

8.6

add-ons.org · PDF for Elementor Forms + Drag And Drop Template Builder

A deserialization of untrusted data vulnerability in the PDF for Elementor Forms plugin allows for object injection, potentially leading to remote code execution.

Executive summary

An object injection vulnerability in the PDF for Elementor Forms plugin allows authenticated attackers to execute arbitrary code, creating a critical risk to site integrity.

Vulnerability

This is a deserialization of untrusted data flaw (CWE-502) that allows an authenticated user to perform object injection. The vulnerability is exploitable over the network by an attacker with low privileges.

Business impact

The ability to perform object injection often leads to remote code execution on the underlying server. Given the CVSS score of 8.6, this vulnerability poses a severe threat to data confidentiality, system integrity, and availability. Compromise of this plugin could allow an attacker to gain full control over the WordPress environment, potentially leading to complete site takeover or lateral movement within the hosting infrastructure.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should monitor the vendor advisory for the release of a security update and apply it immediately upon availability.

Proactive Monitoring: Review web server access logs for anomalous requests targeting the PDF for Elementor Forms plugin endpoints, specifically looking for serialized PHP objects in parameters.

Compensating Controls: If no patch is available, consider disabling the plugin entirely until a secure version is released. A Web Application Firewall with rules designed to block malicious deserialization patterns may provide temporary protection.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the high severity of this object injection flaw, it is imperative to prioritize the removal or update of this plugin. Organizations should proactively audit their WordPress installations for the presence of this plugin and restrict access to administrative or configuration functions to the absolute minimum necessary until a vendor-supplied patch is deployed.