PT-2026-36575 · WordPress · Gravity Forms

Tadokun

·

Published

2026-05-02

·

Updated

2026-05-02

·

CVE-2026-5111

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gravity Forms versions prior to 2.10.1
Description Stored Cross-Site Scripting occurs due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fields. Specifically, repeater subfields bypass state validation checks, and the validate() method for Hidden Product only validates the quantity field, ignoring the product name field. This product name is subsequently output without proper escaping in the get value entry detail() method, allowing unauthenticated attackers to inject arbitrary web scripts through form submissions that execute when an administrator views the entry details.
Recommendations Update to a version later than 2.10.0.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5111

Affected Products

Gravity Forms