CVE-2023-2701
The Gravity Forms plugin for WordPress contained a cross-site scripting vulnerability that could be exploited by an attacker to inject harmful scripts into a website, potentially resulting in the execution of malicious code when visitors access the site. This flaw affected versions prior to 2.7.5 and has been resolved in that version and later. Users should upgrade to version 2.7.5 or newer to eliminate this security risk. The vulnerability was identified and reported by Fioravante Souza through WPScan.
Based on public CVE data (MITRE/NVD).