CVE-2026-49085 is an unauthenticated PHP Object Injection vulnerability in the WordPress plugin WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms. The issue affects versions up to and including 1.1.4. Based on the available information, the flaw allows attacker-controlled serialized PHP data to be processed by the plugin without authentication, resulting in unsafe object deserialization. No specific vulnerable function or code path is provided in the supplied content. The vulnerability is classified as CWE-502 and is rated with CVSS v3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python exploit project consisting of one main script, CVE-2026-49085.py, plus a minimal README. The script targets an alleged unauthenticated PHP object injection flaw in the WordPress WP Insightly / CF7-Insightly plugin, attributed to unsafe use of maybe_unserialize() on user-controlled form data in cf7-insightly.php. The exploit is not part of a larger framework. Repository structure and purpose: the Python file is both the reconnaissance and exploitation entry point. It defines a WPInsightlyExploit class for plugin detection, vulnerability assessment, endpoint discovery, and exploitation, plus a PopChainFinder helper referenced by the CLI for identifying potentially useful gadget-chain sources in installed plugins. The script uses requests for HTTP interaction, regex for version extraction, argparse for CLI control, and BeautifulSoup for parsing pages/forms. Main capabilities observed from the available code: (1) detect whether the target WordPress site has the plugin installed by probing several common plugin directory names; (2) fetch the plugin PHP file and extract/check the version, marking versions <= 1.1.4 as vulnerable; (3) fall back to searching the plugin source for the maybe_unserialize pattern as a heuristic vulnerability indicator; (4) enumerate form-processing endpoints; (5) scan for potential POP-chain-bearing plugins; and (6) attempt exploitation using selectable serialized-object payload profiles such as monolog, swiftmailer, guzzle, doctrine, and WordPress-oriented gadget options. This indicates the script is more than a detector and is intended to operationalize PHP object injection into possible RCE when a gadget chain exists. The attack vector is web-based and unauthenticated. The exploit interacts with WordPress plugin files under /wp-content/plugins/... and appears to rely on reachable form submission functionality to deliver malicious serialized values. Because successful post-deserialization impact depends on the target's available PHP gadget chains, the exploit is best classified as OPERATIONAL rather than fully weaponized: it includes payload options and exploitation logic, but success is environment-dependent rather than guaranteed. Notable fingerprintable targets in the code are the plugin paths /wp-content/plugins/wp-insightly/, /wp-content/plugins/cf7-insightly/, /wp-content/plugins/contact-form-insightly/, and /wp-content/plugins/insightly-contact-form/, specifically probing cf7-insightly.php and readme.txt beneath those directories. No hardcoded external C2, IPs, or third-party domains are visible in the provided content.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.