← WordPress Vulnerabilities
WordPress security by component

Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms

Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest published CVSS base score is 9.8.

Plugin slug: cf7-infusionsoft

CVE-2026-49104: Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms: Code execution

Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.2.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedJun 15, 2026
Known safe version1.2.2
Published vulnerabilities for cf7-infusionsoft
Safe version
Jun 15, 2026 CVE-2026-49104
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms: Code execution
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account. The published affected range is n/a through 1.2.1. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
1.2.2
CVE9.8
NVDPending