Junglewise Threat Intelligence

CVE-2026-9691: WordPress Integration for ActiveCampaign PHP Object Injection

CVE-2026-9691 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Executive brief

A critical security vulnerability exists in a WordPress plugin used to connect popular form builders like Contact Form 7 and Ninja Forms with ActiveCampaign. This flaw allows an unauthenticated attacker to remotely take control of the website or access sensitive data without needing any login credentials. If exploited, this could lead to a total site compromise, data theft, or service disruption.

Technical details

The 'Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms' plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 1.1.1. This vulnerability occurs due to the deserialization of untrusted data (CWE-502) without proper validation. An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker can achieve remote code execution, perform SQL injection, or conduct path traversal. The issue is resolved in version 1.1.2.

Affected products

  • Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1

Timeline

  • 2025-05-17: other: Vulnerability reported by researcher Frissi0n
  • 2026-06-05: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: CVE published to NVD

References