Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.
The plugin improperly deserializes input data from untrusted sources, which is classified as CWE-82 (Improper Neutralization of Script in Attributes of IMG Tags, but in a broader context — deserialization without validation). An attacker with administrator privileges can pass crafted serialized data, which when processed by the application leads to the execution of arbitrary system commands on the server side. The scope of impact includes resources beyond the plugin itself (Scope: Changed), meaning the possibility of affecting the entire system hosting the WordPress site.
An attacker can gain full control over the server — execute arbitrary commands, read and modify system files, and potentially take control of the entire hosting infrastructure. System confidentiality, integrity, and availability are threatened at the highest level.
The Contact Form by Supsystic plugin should be immediately updated to a version higher than 1.7.28. Details regarding the patch are available in the vendor's references and in the Patchstack database. If an immediate update is not possible, it is recommended to deactivate the plugin until the fix is deployed.
WordPress Contact Form by Supsystic plugin in versions from n/a to 1.7.28 inclusive.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H