PT-2026-24658 · Gravity Forms · Gravity Forms

Mikemyers

·

Published

2026-03-11

·

Updated

2026-03-15

·

CVE-2026-3492

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gravity Forms versions prior to 2.9.28.1
Description The Gravity Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is caused by a combination of issues: missing authorization on the create from template API endpoint, which allows any authenticated user to create forms; inadequate input sanitization using sanitize text field(), which allows single quotes; and a lack of output escaping when the form title is displayed in the Form Switcher dropdown, where the title attribute is constructed without esc attr(), and the JavaScript saferHtml utility does not escape quotes. This allows authenticated attackers with Subscriber-level access or higher to inject arbitrary JavaScript that will execute when an Administrator searches within the Form Switcher dropdown in the Form Editor.
Recommendations Update Gravity Forms to version 2.9.28.1 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3492

Affected Products

Gravity Forms