Input validation vulnerability in ActiveCampaign – Forms, Site Tracking, Live Chat 8.1.16

The ActiveCampaign plugin for WordPress has a security issue that can affect versions up to 8.1.16. This vulnerability is called Stored Cross-Site Scripting, and it happens because the plugin doesn’t properly clean or protect against harmful code. This means that someone with high-level access to the website can add harmful code to certain pages, which will then run whenever someone visits those pages. This only affects websites with multiple sites or websites where certain security measures have been turned off.

Detected in:

ActiveCampaign – Forms, Site Tracking, Live Chat fixed vulnerable versions: >= * <= 8.1.16

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.