GravityView <= 3.0.0 - Unauthenticated Insecure Direct Object Reference
mediumThe GravityView plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.1
- Disclosed:
- Jun 26, 2026