PT-2026-36573 · WordPress · Gravity Forms

Tadokun

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-5109

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gravity Forms versions prior to 2.10.1
Description The plugin is subject to Stored Cross-Site Scripting due to insufficient validation and output escaping of Product Option field values. The issue occurs because the state validation function accepts submitted values where the wp kses() sanitized version matches a legitimate option value, but the raw unsanitized value is stored in the database. Unauthenticated attackers can inject arbitrary web scripts into entry data. These scripts execute when an administrator views entry details in the Order Summary section, specifically where the option label is output without escaping in the 'view-order-summary.php' file at line 32.
Recommendations Update to a version later than 2.10.0.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5109

Affected Products

Gravity Forms