Sploitus

CVE-2026-9691

2 known exploits for CVE-2026-9691

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (39th percentile)
Weakness
CWE-502
NVD status
Deferred
Published
2026-06-15
Attack patterns
CAPEC-586

Fix

Update the WordPress Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms plugin to the latest available version (at least 1.1.2).

CVE-2026-9691 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-9691

Proof-of-concept code and exploit modules indexed by Sploitus