Description
WordPress Plugin Google Forms is prone to a vulnerability that lets remote attackers inject and execute arbitrary code because the application fails to sanitize user-supplied input before being passed to the unserialize() PHP function. Attackers can possibly exploit this issue to execute arbitrary PHP code within the context of the affected webserver process. WordPress Plugin Google Forms version 0.87 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.91 or latest
References
http://seclists.org/oss-sec/2017/q1/199
http://www.openwall.com/lists/oss-security/2017/01/25/16
https://packetstormsecurity.com/files/140727/WordPress-Google-Forms-0.87-PHP-Object-Injection.html
Related Vulnerabilities
WordPress Plugin GS Portfolio for Envato Cross-Site Scripting (1.3.8)
Oracle Database Server CVE-2014-6563 Vulnerability (CVE-2014-6563)
WordPress Plugin Newsletter-Send awesome emails from WordPress Cross-Site Scripting (3.2.6)
WordPress Plugin Google Analytics Counter Tracker PHP Object Injection (3.4.0)
WordPress Plugin WP ALL Export Pro Multiple Vulnerabilities (1.7.8)