CVE-2026-5109
The Gravity Forms plugin for WordPress has a vulnerability in versions up to 2.10.0 that allows attackers to inject malicious JavaScript code into the plugin's database. This occurs when the plugin fails to properly sanitize and escape user input for Product Option fields, allowing attackers to inject arbitrary web scripts that will execute when an administrator views the entry details. As a result, unauthenticated attackers can inject malicious code that will execute when an administrator accesses the entry details page, potentially leading to further exploitation.
Based on public CVE data (MITRE/NVD).