ActiveDEMAND
ActiveDEMAND has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 7.4, and the most serious one scores 10.0 out of 10. Severity breakdown: 2 critical and 0 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF), Unrestricted Upload Of File With Dangerous Type.
Every one of the 4 issues recorded for ActiveDEMAND has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. ActiveDEMAND is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-32809ActiveDEMAND <= 0.2.41 - Unauthenticated Arbitrary File Upload
Read the full analysisVulnerability Records

Adds the ActiveDEMAND tracking script to your website. As well this plugin gives you the ability to use shortcodes to embed ActiveDEMAND webforms into your widgets, pages, posts, and sidebars. Personalize your WordPress visitor Experience with ActiveDEMAND Dynamically change website content based on users GEO-IP location, utm_source/medium, any visitor history/context Embed web forms on any page/post/sidebar etc Add custom popups and opt in bars Automatically send emails to people who fill out forms Track visitors, link clicks etc GEO IP lookup of all visitors, email opens, phone calls, etc Full attribution of marketing activities Appointment Scheduling For the full list of capabilities, visit www.ActiveDEMAND.com! Fully automate your marketing with ActiveDEMAND.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C