Description
WordPress Plugin Google Forms is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input before being passed to the unserialize() PHP function. Attackers can possibly exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Google Forms version 0.87 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.91 or latest
References
http://seclists.org/oss-sec/2017/q1/199
http://www.openwall.com/lists/oss-security/2017/01/25/16
https://packetstormsecurity.com/files/140727/WordPress-Google-Forms-0.87-PHP-Object-Injection.html
Related Vulnerabilities
WordPress Plugin Donation Block For PayPal Unspecified Vulnerability (1.0.0)
WordPress Plugin LittleBot ACH for Stripe + Plaid Unspecified Vulnerability (1.2.6)
Oracle JRE CVE-2019-2999 Vulnerability (CVE-2019-2999)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-4043)