CVE-2026-9691 is an unauthenticated PHP Object Injection vulnerability affecting the WordPress plugin Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms in versions up to and including 1.1.1. The available source material identifies the issue as PHP object injection but does not provide the specific vulnerable function, sink, or code path. Because the flaw is reachable without authentication, a remote attacker can supply crafted serialized PHP data to the vulnerable plugin and trigger unsafe object deserialization behavior. The weakness is classified as CWE-502.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python proof-of-concept/operational exploit for CVE-2026-9691, containing one main script (CVE-2026-9691.py) and a brief README. The script targets a WordPress ActiveCampaign integration plugin vulnerable to unauthenticated PHP object injection through unsafe deserialization of form field values using maybe_unserialize(). The exploit is structured as a command-line tool with an ActiveCampaignExploit class and a main() entry point. Based on the visible code, it performs staged reconnaissance and exploitation: it first probes several likely WordPress plugin installation paths, then fetches the plugin PHP file to determine version or detect the vulnerable code pattern, and exposes CLI modes for plugin detection, vulnerability checking, Contact Form 7 form discovery, form analysis, POP-chain discovery, and full exploitation using a supplied payload. Notable capabilities include: identifying whether the plugin is installed, checking whether the version appears vulnerable (<= 1.1.1), enumerating forms that may expose the vulnerable processing path, and attempting to deliver a serialized object payload. The script uses requests sessions with a browser-like User-Agent and appears intended for remote unauthenticated web exploitation. Because the provided content is truncated, some helper methods are not fully visible, but the CLI and class naming strongly indicate end-to-end exploit workflow rather than mere detection. There are no hardcoded external C2 or callback endpoints visible in the provided content. The fingerprintable targets are local WordPress plugin paths under /wp-content/plugins/ and the plugin files cf7-active-campaign.php and readme.txt. Overall, this is a standalone web exploit tool with operational payload delivery capability, but the final impact depends on the target environment containing a usable PHP POP gadget chain.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.