Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign activecampaign-subscription-forms allows Stored XSS.This issue affects ActiveCampaign: from n/a through <= 8.1.16.
Published: 2025-04-04
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper neutralization of input during web page generation in the ActiveCampaign WordPress plugin, from the earliest released version up through 8.1.16, allows stored cross‑site scripting. The vulnerability arises when user‑supplied data is saved and later rendered without proper sanitization, permitting malicious scripts to be embedded in the site’s content.

Affected Systems

The affected product is the ActiveCampaign WordPress subscription‑forms plugin, in all versions up to and including 8.1.16. All installations that have not upgraded beyond 8.1.16 are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium‑severity risk, while the EPSS score of less than 1% suggests that exploitation probability is currently very low. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw by submitting malicious input through the subscription forms, with no privileged access or external network exploitation required. Successful exploitation would cause arbitrary script execution in the context of any user who views the rendered content, potentially enabling various malicious actions.

Generated by OpenCVE AI on May 1, 2026 at 11:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ActiveCampaign WordPress subscription‑forms plugin to a version newer than 8.1.16 to remove the stored XSS flaw.
  • If an immediate update is not possible, temporarily remove or disable any public‑facing subscription forms provided by the plugin to stop new malicious input from being captured.
  • Add a strict content‑security‑policy that disallows inline scripts and restricts script sources to mitigate residual XSS risk.
  • Investigate the database for any previously stored malicious scripts and remove them.

Generated by OpenCVE AI on May 1, 2026 at 11:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9873 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign activecampaign-subscription-forms allows Stored XSS.This issue affects ActiveCampaign: from n/a through <= 8.1.16.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Fri, 04 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign allows Stored XSS. This issue affects ActiveCampaign: from n/a through 8.1.16.
Title WordPress ActiveCampaign Plugin <= 8.1.16 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:17.013Z

Reserved: 2025-04-04T10:00:42.738Z

Link: CVE-2025-32136

cve-icon Vulnrichment

Updated: 2025-04-04T19:54:50.031Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:21.723

Modified: 2026-04-23T15:28:37.423

Link: CVE-2025-32136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T11:30:15Z

Weaknesses