CVE · High

CVE-2020-13764 — Gravity Forms [gravityforms] < 2.4.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-13764 Gravity Forms [gravityforms] < 2.4.9 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 2.4.9 2.4.9 2019-05-08

CVE-2020-13764

The Gravity Forms plugin versions prior to 2.4.9 contain a flaw in common.php where hashed passwords can be exposed through the $current_user->get($property) function call because user_pass is not treated as a restricted field that requires special handling.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.