CVE-2026-49105 is an unauthenticated PHP Object Injection vulnerability in the WordPress plugin "WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms." The issue affects versions up to and including 1.1.4. The available content identifies the flaw as PHP Object Injection, which implies attacker-controlled serialized PHP data is accepted and unserialized by the plugin without proper validation. No vulnerable function or code path is provided in the supplied material. The vulnerability is remotely exploitable over the network, requires no authentication, and requires no user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python exploit project consisting of one main script (CVE-2026-49105.py) and a minimal README. The script targets CVE-2026-49105, described as an unauthenticated PHP object injection flaw in a WordPress Zendesk/Contact Form 7 integration plugin caused by unsafe maybe_unserialize() use on attacker-controlled form data. The exploit is structured as a CLI tool with a ZendeskExploit class and multiple operational modes. Based on the visible code, it supports: plugin detection by probing common WordPress plugin paths; vulnerability assessment by retrieving the plugin PHP file and checking version strings or vulnerable code patterns; Contact Form 7 form discovery; form analysis through a CF7FormAnalyzer helper; POP-chain discovery; and a full exploit path that accepts a user-provided payload. This indicates the repository is more than a detector and is intended to facilitate actual exploitation when the target environment is suitable. Primary capability is unauthenticated web exploitation against WordPress sites. The script uses requests.Session with a browser-like User-Agent and interacts over HTTP(S) with predictable WordPress plugin file locations. The most fingerprintable targets are plugin directories under /wp-content/plugins/ and the main file cf7-zendesk.php, plus readme.txt for passive confirmation. The vulnerability check specifically treats versions <= 1.1.4 as vulnerable and also searches for the string maybe_unserialize in the plugin source. Operationally, the exploit appears to require a reachable vulnerable plugin installation and likely a valid Contact Form 7 workflow to deliver malicious serialized input. Because PHP object injection generally needs a gadget chain for high-impact outcomes, the script’s mention of POP-chain finding suggests exploitation success may range from proof-of-vulnerability to remote code execution depending on installed classes/plugins on the target. Overall maturity is operational rather than framework-grade weaponized: it includes exploitation logic and helper enumeration features, but payloading is user-supplied rather than deeply automated.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.