plugin

Gravityforms Vulnerabilities

62 known security issues reported for the Gravityforms WordPress plugin. Most recent disclosed Jul 15, 2026.

12 critical 12 high 13 medium

Running Gravityforms on your site? Check whether your installed version is affected.

Scan your site free

Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter

high

The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information...

CVSS:
7.5
Affected:
up to 2.10.4
Fixed in:
2.10.5
Disclosed:
Jul 15, 2026

CVE-2026-12997 on NVD →

Gravity Forms <= 2.10.0.1 - Unauthenticated Arbitrary File Deletion

critical

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.10.0.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the r...

CVSS:
9.1
Affected:
up to 2.10.0.1
Fixed in:
2.10.1
Disclosed:
Jun 1, 2026

CVE-2026-48866 on NVD →

Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input

high

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.9.30. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state valid...

CVSS:
7.2
Affected:
up to 2.9.30
Fixed in:
2.9.31
Disclosed:
May 1, 2026

CVE-2026-5113 on NVD →

Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater

high

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names when rendered inside Repeater fields. The validate() method in the GF_Fi...

CVSS:
7.2
Affected:
up to 2.10.0
Fixed in:
2.10.1
Disclosed:
May 1, 2026

CVE-2026-5112 on NVD →

Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Product Option

high

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses...

CVSS:
7.2
Affected:
up to 2.10.0
Fixed in:
2.10.1
Disclosed:
May 1, 2026

CVE-2026-5109 on NVD →

Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater

high

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields, where repeater subfields bypass state validation checks and the Hi...

CVSS:
7.2
Affected:
up to 2.10.0
Fixed in:
2.10.1
Disclosed:
May 1, 2026

CVE-2026-5111 on NVD →

Gravity Forms <= 2.10.0 - Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater

high

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater...

CVSS:
7.2
Affected:
up to 2.10.0
Fixed in:
2.10.1
Disclosed:
May 1, 2026

CVE-2026-5110 on NVD →

Gravity Forms <= 2.9.30 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field

medium

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method in the `GF_Field_CreditCard` class outputting the card type value with...

CVSS:
6.1
Affected:
up to 2.9.30
Fixed in:
2.9.31
Disclosed:
Apr 7, 2026

CVE-2026-4394 on NVD →

Gravity Forms <= 2.9.30 - Reflected Cross-Site Scripting via 'form_ids' Parameter

medium

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `form_ids` parameter in the `gform_get_config` AJAX action in all versions up to, and including, 2.9.30. This is due to the `GFCommon::send_json()` method outputting JSON-encoded data wrapped in HTML comment delimiters using...

CVSS:
4.7
Affected:
up to 2.9.30
Fixed in:
2.9.31
Disclosed:
Apr 7, 2026

CVE-2026-4406 on NVD →

Gravity Forms - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title vulnerability

medium

Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title vulnerability

CVSS:
6.5
Affected:
up to 2.9.28
Fixed in:
2.9.29
Disclosed:
Mar 12, 2026

Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title

medium

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input sanitiza...

CVSS:
6.4
Affected:
up to 2.9.28
Fixed in:
2.9.29
Disclosed:
Mar 10, 2026

CVE-2026-3492 on NVD →

Gravity Forms < 2.9.29 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title

high
Affected:
up to 2.9.29
Fixed in:
2.9.29
Disclosed:
Mar 10, 2026

CVE-2026-3492 on NVD →

Gravity Forms [gravityforms] < 2.9.23.1

unknown

[en] The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

Affected:
up to 2.9.23.1
Fixed in:
2.9.23.1
Disclosed:
Dec 24, 2025

CVE-2025-13407 on NVD →

Gravity Forms <= 2.9.23.0 - Unauthenticated Arbitrary File Upload

critical

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 2.9.23.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possib...

CVSS:
9.8
Affected:
up to 2.9.23.0
Fixed in:
2.9.23.1
Disclosed:
Dec 3, 2025

CVE-2025-13407 on NVD →

GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload

critical
Affected:
up to 2.9.23.1
Fixed in:
2.9.23.1
Disclosed:
Dec 3, 2025

CVE-2025-13407 on NVD →

Gravity Forms [gravityforms] < 2.9.22

unknown

[en] The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked uploa...

Affected:
up to 2.9.22
Fixed in:
2.9.22
Disclosed:
Nov 18, 2025

CVE-2025-12974 on NVD →

Gravity Forms <= 2.9.21.1 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload

high

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the legacy chunked upload mechanism in all versions up to, and including, 2.9.21.1. This is due to the extension blacklist not including .phar files, which can be uploaded through the chunked upload mec...

CVSS:
8.1
Affected:
up to 2.9.21.1
Fixed in:
2.9.22
Disclosed:
Nov 17, 2025

CVE-2025-12974 on NVD →

Gravity Forms < 2.9.22 - Unauthenticated Arbitrary File Upload via Legacy Chunked Upload

critical
Affected:
up to 2.9.22
Fixed in:
2.9.22
Disclosed:
Nov 17, 2025

CVE-2025-12974 on NVD →

Gravity Forms [gravityforms] < 2.9.21

unknown

[en] The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may m...

Affected:
up to 2.9.21
Fixed in:
2.9.21
Disclosed:
Nov 7, 2025

CVE-2025-12352 on NVD →

Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'

critical

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make r...

CVSS:
9.8
Affected:
up to 2.9.20
Fixed in:
2.9.21
Disclosed:
Nov 6, 2025

CVE-2025-12352 on NVD →

Gravity Forms 2.9.18 - 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'

critical
Affected:
2.9.18 – 2.9.21
Fixed in:
2.9.21
Disclosed:
Nov 6, 2025

CVE-2025-12352 on NVD →

GravityForms 2.9.11.1 / 2.9.12 - Malware Compromise

unknown
Affected:
2.9.11.1 – 2.9.13
Fixed in:
2.9.13
Disclosed:
Jul 11, 2025

Gravity Forms [gravityforms] < 2.9.2

unknown

[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Jan 17, 2025

CVE-2024-13377 on NVD →

Gravity Forms [gravityforms] < 2.9.2

unknown

[en] The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Jan 17, 2025

CVE-2024-13378 on NVD →

GravityForms <= 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter

high

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...

CVSS:
7.2
Affected:
up to 2.9.1.3
Fixed in:
2.9.2
Disclosed:
Jan 16, 2025

CVE-2024-13377 on NVD →

GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter

medium

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
5.4
Affected:
2.9.0.1 – 2.9.1.3
Fixed in:
2.9.2
Disclosed:
Jan 16, 2025

CVE-2024-13378 on NVD →

GravityForms 2.9.0.1 - 2.9.1.3 - Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter

high
Affected:
2.9.0.1 – 2.9.2
Fixed in:
2.9.2
Disclosed:
Jan 16, 2025

CVE-2024-13378 on NVD →

GravityForms < 2.9.2 - Unauthenticated Stored Cross-Site Scripting via 'alt' parameter

high
Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Jan 16, 2025

CVE-2024-13377 on NVD →

Gravity Forms [gravityforms] < 2.7.4

unknown

[en] Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.

Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
Dec 20, 2023

CVE-2023-28782 on NVD →

Gravity Forms [gravityforms] < 2.0.7

unknown

Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests v...

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Oct 13, 2023

Gravity Forms [gravityforms] < 2.7.5

unknown

[en] The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.

Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Jul 17, 2023

CVE-2023-2701 on NVD →

Gravity Forms <= 2.7.4 - Reflected Cross-Site Scripting

medium

The Gravity Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in versions up to, and including, 2.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 2.7.4
Fixed in:
2.7.5
Disclosed:
Jun 21, 2023

CVE-2023-2701 on NVD →

Gravity Forms < 2.7.5 - Reflected XSS

medium
Affected:
up to 2.7.5
Fixed in:
2.7.5
Disclosed:
Jun 21, 2023

CVE-2023-2701 on NVD →

Gravity Forms [gravityforms] < 1.8.20

unknown

Upgrade the plugin. Abk Khan discovered and reported this Local File Inclusion vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to include local files of the target website and show its output onto the screen. Files which store credentials, such as database credentials, could potenti...

Affected:
up to 1.8.20
Fixed in:
1.8.20
Disclosed:
Jun 17, 2023

Gravity Forms <= 2.7.3 - Unauthenticated PHP Object Injection

critical

The Gravity Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.3 via deserialization of untrusted input in the get_field_input function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is p...

CVSS:
9.8
Affected:
up to 2.7.3
Fixed in:
2.7.4
Disclosed:
May 29, 2023

CVE-2023-28782 on NVD →

Gravity Forms < 2.7.4 - Unauthenticated PHP Object Injection

critical
Affected:
up to 2.7.4
Fixed in:
2.7.4
Disclosed:
May 29, 2023

CVE-2023-28782 on NVD →

Gravity Forms [gravityforms] < 1.9.7

unknown

Update the plugin to the latest version. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be...

Affected:
up to 1.9.7
Fixed in:
1.9.7
Disclosed:
Apr 20, 2023

Gravity Forms [gravityforms] < 1.9.3.6

unknown

Update the plugin. An unknown person discovered and reported this SQL Injection vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to directly interact with your database, including but not limited to stealing information. This vulnerability has been fixed in version 1.9.3.6.

Affected:
up to 1.9.3.6
Fixed in:
1.9.3.6
Disclosed:
Mar 17, 2023

Gravity Forms [gravityforms] < 1.9.16

unknown

Update the plugin. Henri Salo discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Gravity Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit yo...

Affected:
up to 1.9.16
Fixed in:
1.9.16
Disclosed:
Mar 1, 2023

Gravity Forms [gravityforms] < 2.4.9

unknown

[en] common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Jun 2, 2020

CVE-2020-13764 on NVD →

Gravityforms <= 2.4.8 - Information Exposure

high

common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.

CVSS:
7.5
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
May 8, 2019

CVE-2020-13764 on NVD →

GravityForms < 2.4.9 - Hashed Password Leakage

unknown
Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
May 8, 2019

CVE-2020-13764 on NVD →

Gravity Forms < 2.0.7 - Authenticated Blind Cross-Site Scripting (XSS)

medium
Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Oct 13, 2016

Gravity Forms <= 2.0.6.5 - Cross-Site Scripting

medium

WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal...

CVSS:
5.4
Affected:
up to 2.0.6.5
Fixed in:
2.0.7
Disclosed:
Sep 7, 2016

Gravity Forms [gravityforms] < 2.0.7

unknown

WordPress Plugin Gravity Forms is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal...

Affected:
up to 2.0.7
Fixed in:
2.0.7
Disclosed:
Sep 7, 2016

Gravityforms <= 1.9.15.11 - Cross-Site Scripting

medium

The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a us...

CVSS:
4.7
Affected:
up to 1.9.15.11
Fixed in:
1.9.16
Disclosed:
Mar 1, 2016

Gravity Forms < 1.9.16 - Authenticated Reflected Cross-Site Scripting (XSS)

medium
Affected:
up to 1.9.16
Fixed in:
1.9.16
Disclosed:
Mar 1, 2016

Gravity Forms [gravityforms] < 1.9.16

unknown

The Gravityforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting up to, and including, 1.9.15.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a us...

Affected:
up to 1.9.16
Fixed in:
1.9.16
Disclosed:
Mar 1, 2016

Gravityforms <= 1.9.6 - Cross-Site Scripting

medium

The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping alongside the use of add_query_arg or remove_query_arg(). This makes it possible for attackers to inject arbitrary web scripts that execute in a...

CVSS:
5.4
Affected:
up to 1.9.6
Fixed in:
1.9.7
Disclosed:
Apr 20, 2015

Gravity Forms <= 1.9.6 - Cross-Site Scripting (XSS)

medium
Affected:
up to 1.9.7
Fixed in:
1.9.7
Disclosed:
Apr 20, 2015

Gravity Forms [gravityforms] < 1.9.7

unknown

The Gravityforms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.9.6 due to insufficient input sanitization and output escaping alongside the use of add_query_arg or remove_query_arg(). This makes it possible for attackers to inject arbitrary web scripts that execute in a...

Affected:
up to 1.9.7
Fixed in:
1.9.7
Disclosed:
Apr 20, 2015

Gravityforms <= 1.9.3.5 - SQL Injection

critical

The Gravifyforms plugin for WordPress is vulnerable to blind SQL Injection via the ‘sort_column GET’ parameter in versions up to, and including,1.9.3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...

CVSS:
9.1
Affected:
up to 1.9.3.5
Fixed in:
1.9.3.6
Disclosed:
Mar 17, 2015

CVE-2015-2260 on NVD →

Gravity Forms 1.8 <= 1.9.3.5 - Authenticated Blind SQL Injection

critical
Affected:
up to 1.9.3.6
Fixed in:
1.9.3.6
Disclosed:
Mar 17, 2015

Gravityforms <= 1.8.19 - Arbitrary File Upload

critical

The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the includes/upload.php file in versions up to, and including, 1.8.19. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote c...

CVSS:
9.8
Affected:
up to 1.8.20
Fixed in:
1.8.20
Disclosed:
Feb 26, 2015

Gravity Forms [gravityforms] < 1.8.20

unknown

The Gravityforms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the includes/upload.php file in versions up to, and including, 1.8.19. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote c...

Affected:
up to 1.8.20
Fixed in:
1.8.20
Disclosed:
Feb 26, 2015

Gravity Forms <= 1.8.19 - Arbitrary File Upload

critical
Affected:
up to 1.8.20
Fixed in:
1.8.20
Disclosed:
Dec 8, 2014

Gravity Forms [gravityforms] >= 1.8 - <= 1.9.3.5

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
1.8 – 1.9.3.5
Fixed in:
1.9.3.5

CVE-2015-2260 on NVD →

Gravity Forms [gravityforms] < 1.8.20

unknown

The gravityforms WordPress plugin was affected by an Arbitrary File Upload security vulnerability.

Affected:
up to 1.8.20
Fixed in:
1.8.20

Gravity Forms [gravityforms] < 1.9.3.6

unknown

Title: Gravity Forms 1.8 &lt;= 1.9.3.5 - Blind SQL Injection CVE-2015-2260 Version/s Tested: 1.9.3.1 Description: Gravity Forms is one of the most popular WordPress plugins (gravityforms) used to create forms for WordPress sites. The latest version at the time of writing (1.9.3.5) contains an authenticated (admi...

Affected:
up to 1.9.3.6
Fixed in:
1.9.3.6

Gravity Forms [gravityforms] < 1.9.7

unknown

The gravityforms WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.9.7
Fixed in:
1.9.7

Gravity Forms [gravityforms] < 1.9.16

unknown

The gravityforms WordPress plugin was affected by a Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.9.16
Fixed in:
1.9.16

Gravity Forms [gravityforms] < 2.0.7

unknown

A blind XSS vulnerability exists in the GravityForms plugin prior to version 2.0.7, in the select option dropdown boxes on forms. If the select column is displayed on the gf_entries page when viewed in the Dashboard, the code is executed by the admin / viewer of the submissions. This vulnerability was responsibly di...

Affected:
up to 2.0.7
Fixed in:
2.0.7

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database