Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

2 vulnerability records

HighCVE-2026-49104

Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 - Unauthenticated PHP Object Injection

Affected versions: *-1.2.1

Vulnerability type: CWE-502 Deserialization of Untrusted Data

Affected software, patched versions and attribution

The Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms

Affected versions: *-1.2.1

Patched versions: 1.2.2

Researcher credit: Frissi0n

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
June 5, 2026
CVSS
8.1
Medium

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

WP Gravity Forms HubSpot: Currently marked unpatchedIntegration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms: Currently marked unpatchedWP Gravity Forms Constant Contact Plugin: Currently marked unpatchedDatabase for Contact Form 7, WPforms, Elementor forms: Currently marked unpatchedWP Gravity Forms Insightly: Currently marked unpatchedIntegration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms: Currently marked unpatchedWP Gravity Forms Dynamics CRM: Currently marked unpatchedIntegration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms: Currently marked unpatchedIntegration for HubSpot and WooCommerce: Currently marked unpatchedIntegration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms: Currently marked unpatchedWP Gravity Forms Zendesk: Currently marked unpatchedCRM Perks Integration for Gravity Forms and Salesforce: Currently marked unpatchedIntegration for Gravity Forms and Pipedrive: Currently marked unpatchedWP Gravity Forms Keap/Infusionsoft: Currently marked unpatchedIntegration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms: Currently marked unpatchedWP Gravity Forms Zoho CRM and Bigin: Currently marked unpatchedWP Gravity Forms FreshDesk Plugin: Currently marked unpatchedIntegration for WooCommerce and Salesforce: Currently marked unpatchedWP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: Currently marked unpatchedConnector for Gravity Forms and Google Sheets: Currently marked unpatchedWP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin: Currently marked unpatchedIntegration for WooCommerce and QuickBooks: Currently marked unpatchedWP Keap/Infusionsoft WooCommerce Plugin: Currently marked unpatchedIntegration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin: Currently marked unpatchedWP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms: Currently marked unpatchedIntegration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms: Currently marked unpatchedIntegration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms: Currently marked unpatched

Affected versions: *-1.0.8; *-1.2.5; *-1.0.5; *-1.2.1; *-1.0.6; *-1.1.3; *-1.0.7; *-1.0.3

Vulnerability type: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected software, patched versions and attribution

Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

WP Gravity Forms HubSpot

Affected versions: *-1.0.8

Patched versions: 1.0.9

Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms

Affected versions: *-1.2.5

Patched versions: 1.2.6

WP Gravity Forms Constant Contact Plugin

Affected versions: *-1.0.5

Patched versions: 1.0.6

Database for Contact Form 7, WPforms, Elementor forms

Affected versions: *-1.2.1

Patched versions: 1.2.2

WP Gravity Forms Insightly

Affected versions: *-1.0.6

Patched versions: 1.0.7

Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms

Affected versions: *-1.1.3

Patched versions: 1.1.4

WP Gravity Forms Dynamics CRM

Affected versions: *-1.0.7

Patched versions: 1.0.8

Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms

Affected versions: *-1.0.3

Patched versions: 1.0.4

Integration for HubSpot and WooCommerce

Affected versions: *-1.0.4

Patched versions: 1.0.5

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms

Affected versions: *-1.1.0

Patched versions: 1.1.1

WP Gravity Forms Zendesk

Affected versions: *-1.0.7

Patched versions: 1.0.8

CRM Perks Integration for Gravity Forms and Salesforce

Affected versions: *-1.2.5

Patched versions: 1.2.6

Integration for Gravity Forms and Pipedrive

Affected versions: *-1.0.6

Patched versions: 1.0.7

WP Gravity Forms Keap/Infusionsoft

Affected versions: *-1.1.4

Patched versions: 1.1.5

Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms

Affected versions: *-1.1.0

Patched versions: 1.1.1

WP Gravity Forms Zoho CRM and Bigin

Affected versions: *-1.1.5

Patched versions: 1.1.6

WP Gravity Forms FreshDesk Plugin

Affected versions: *-1.2.8

Patched versions: 1.2.9

Integration for WooCommerce and Salesforce

Affected versions: *-1.5.8

Patched versions: 1.5.9

WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

Affected versions: *-1.0.8

Patched versions: 1.0.9

Connector for Gravity Forms and Google Sheets

Affected versions: *-1.1.0

Patched versions: 1.1.1

WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

Affected versions: *-1.1.8

Patched versions: 1.1.9

Integration for WooCommerce and QuickBooks

Affected versions: *-1.1.8

Patched versions: 1.1.9

WP Keap/Infusionsoft WooCommerce Plugin

Affected versions: *-1.0.8

Patched versions: 1.0.9

Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin

Affected versions: *-1.2.3

Patched versions: 1.2.4

WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms

Affected versions: *-1.0.7

Patched versions: 1.0.8

Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms

Affected versions: *-1.0.9

Patched versions: 1.1.0

Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms

Affected versions: *-1.1.9

Patched versions: 1.2.0

Researcher credit: WPScanTeam

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
August 26, 2021
CVSS
6.1

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.