CVE-2023-28782
The Gravity Forms plugin through version 2.7.3 contains a PHP Object Injection vulnerability in the get_field_input function that processes unserialized data without proper validation, permitting unauthenticated users to introduce malicious objects. While the plugin itself lacks a gadget chain to exploit this directly, an attacker could leverage a POP chain from other installed plugins or themes to achieve arbitrary file deletion, access confidential information, or achieve remote code execution. The vulnerability was resolved in version 2.7.4.
Based on public CVE data (MITRE/NVD).