plugin

Infusionsoft Vulnerabilities

3 known security issues reported for the Infusionsoft WordPress plugin. Most recent disclosed Sep 2, 2016.

1 critical 2 medium

Running Infusionsoft on your site? Check whether your installed version is affected.

Scan your site free

Infusionsoft Gravity Forms Add-on <= 1.5.11 - Reflected Cross-Site Scripting

medium

Reflected XSS in wordpress plugin infusionsoft v1.5.11 via the 'ContactId' parameter.

CVSS:
6.1
Affected:
up to 1.5.12
Fixed in:
1.5.12
Disclosed:
Sep 2, 2016

CVE-2016-1000139 on NVD →

Infusionsoft Gravity Forms Add-on 1.5.3 - 1.5.10 - Arbitrary File Upload

critical

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.

CVSS:
9.8
Affected:
1.5.3 – 1.5.10
Fixed in:
1.5.11
Disclosed:
Oct 6, 2014

CVE-2014-6446 on NVD →

Infusionsoft Gravity Forms Add-on < 1.5.7 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in tests/notAuto_test_ContactService_pauseCampaign.php in the Infusionsoft Gravity Forms plugin before 1.5.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) go, (2) contactId, or (3) campaignId parameter.

CVSS:
6.1
Affected:
up to 1.5.7
Fixed in:
1.5.7
Disclosed:
May 25, 2014

CVE-2014-4536 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database