Detects the Contact Form Entries WordPress plugin at version 1.4.7 or earlier, where the download_csv function deserializes form field data using maybe_unserialize() without object type restrictions. Combined with a POP chain from another plugin, an unauthenticated attacker can achieve file deletion, data theft, or remote code execution.
Is your app exploitable through CVE-2026-2599?
Scan your domain free