CVE-2026-9691

Published Jun 15, 2026

Last updated 3 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-9691 describes an unauthenticated PHP Object Injection vulnerability. This flaw impacts versions up to and including 1.1.1 of an integration designed for ActiveCampaign and various form plugins, specifically Contact Form 7, WPForms, Elementor, and Ninja Forms. The vulnerability stems from the improper handling of PHP objects, which could allow an attacker to inject malicious code without requiring authentication.

Description
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
Source
audit@patchstack.com
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

audit@patchstack.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

5