CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-48042

CVSS 9.1v3.1pub. 2024-10-16upd. 2026-04-23

Deserialization of Untrusted Data vulnerability in supsystic Contact Form by Supsystic contact-form-by-supsystic allows Command Injection.This issue affects Contact Form by Supsystic: from n/a through <= 1.7.28.

🤖 AI Analysis
How it works

The plugin improperly deserializes input data from untrusted sources, which is classified as CWE-82 (Improper Neutralization of Script in Attributes of IMG Tags, but in a broader context — deserialization without validation). An attacker with administrator privileges can pass crafted serialized data, which when processed by the application leads to the execution of arbitrary system commands on the server side. The scope of impact includes resources beyond the plugin itself (Scope: Changed), meaning the possibility of affecting the entire system hosting the WordPress site.

Impact

An attacker can gain full control over the server — execute arbitrary commands, read and modify system files, and potentially take control of the entire hosting infrastructure. System confidentiality, integrity, and availability are threatened at the highest level.

Mitigation & patch

The Contact Form by Supsystic plugin should be immediately updated to a version higher than 1.7.28. Details regarding the patch are available in the vendor's references and in the Patchstack database. If an immediate update is not possible, it is recommended to deactivate the plugin until the fix is deployed.

Who is affected

WordPress Contact Form by Supsystic plugin in versions from n/a to 1.7.28 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References