S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2016-1000139 Scanner

CVE-2016-1000139 scanner - Cross-Site Scripting (XSS) vulnerability in Infusionsoft Gravity Forms Add-on

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2016-1000139
6.1
CVSS

Reflected XSS in wordpress plugin infusionsoft v1.5.11

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Infusionsoft Gravity Forms Add-on is a Wordpress plugin used to integrate Infusionsoft with Gravity Forms for efficient lead generation. This plugin lets users capture leads from their website and easily transfer them to Infusionsoft for further marketing automation. The plugin is widely used by marketers and businesses across various industries who want to streamline their lead generation process and manage their leads effectively.

The CVE-2016-1000139 vulnerability is a serious security issue detected in the Infusionsoft Gravity Forms Add-on. This vulnerability allows attackers to inject malicious code into web pages, leading to a type of attack called Reflected Cross-Site Scripting (XSS). Using this vulnerability, attackers can steal sensitive information, launch phishing attacks, and even take full control of the affected website. This vulnerability was discovered and reported in 2016, and it affects the Infusionsoft Gravity Forms Add-on version 1.5.11 and earlier.

When exploited, this vulnerability can lead to significant risks for website owners and users. Attackers can use the injected code to steal login credentials, extract personal information, or launch attacks that affect site visitors. Additionally, such attacks can result in severe reputational damage and legal liability for businesses.

In summary, the Infusionsoft Gravity Forms Add-on is a critical plugin for efficient lead generation on Wordpress. Still, with the emergence of the CVE-2016-1000139 vulnerability, website owners using this plugin must take necessary measures to protect their assets. At s4e.io, we help website owners secure and protect their digital assets, including using pro features that enable efficient identification and remediation of vulnerabilities. By leveraging our platform, users can worry less about threats and focus more on growing their businesses.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners using the Infusionsoft Gravity Forms Add-on must take specific precautions, such as:

  • Updating to the latest version of the plugin
  • Removing unused plugins and themes
  • Implementing a strong firewall solution
  • Securing login credentials with a password manager
  • Using a reputable web application scanner to identify vulnerabilities

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2016-1000139 scanner - Cross-Site Scripting (XSS) vulnerability in Infusionsoft Gravity Forms Add-on | S4E