CVE · High

CVE-2023-28782 — Gravity Forms [gravityforms] < 2.7.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-28782 Gravity Forms [gravityforms] < 2.7.4 Deserialization of Untrusted Data High 8.3 < 2.7.4 2.7.4 2023-05-29

CVE-2023-28782

The Gravity Forms plugin through version 2.7.3 contains a PHP Object Injection vulnerability in the get_field_input function that processes unserialized data without proper validation, permitting unauthenticated users to introduce malicious objects. While the plugin itself lacks a gadget chain to exploit this directly, an attacker could leverage a POP chain from other installed plugins or themes to achieve arbitrary file deletion, access confidential information, or achieve remote code execution. The vulnerability was resolved in version 2.7.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.