All verified exploits

CVE-2026-2599 Contact Form Entries PHP Object Injection

Deterministic critical Contact Form Entries Added cve-verified-cve-2026-2599

Detects the Contact Form Entries WordPress plugin at version 1.4.7 or earlier, where the download_csv function deserializes form field data using maybe_unserialize() without object type restrictions. Combined with a POP chain from another plugin, an unauthenticated attacker can achieve file deletion, data theft, or remote code execution.

Is your app exploitable through CVE-2026-2599?

Scan your domain free