CyberRota Analysis
AI-GeneratedThe vulnerability in Ultimate Addons for Contact Form 7 versions up to 3.5.51 allows for PHP Object Injection, which can be exploited to execute arbitrary PHP code on the server. This poses a significant risk as it could lead to unauthorized access, data manipulation, or complete system compromise. Organizations using this plugin should prioritize patching or upgrading to mitigate potential exploitation.
CVE
CVE-2026-96833
Severity
HIGH
CVSS
7.2
EPSS
0.40%
Original NVD Description
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.