← WordPress Vulnerabilities
WordPress security by component

Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms

Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: cf7-active-campaign

CVE-2026-9691: Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms: Code execution

Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.1.1.

PublishedJun 15, 2026
Known safe version1.1.2
Safe version
Jun 15, 2026 CVE-2026-9691
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms: Code execution
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.1.1.
1.1.2
CVE9.8
NVDPending