CVE · High

CVE-2026-5109 — Gravity Forms [gravityforms] < 2.10.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5109 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01

CVE-2026-5109

The Gravity Forms plugin for WordPress has a vulnerability in versions up to 2.10.0 that allows attackers to inject malicious JavaScript code into the plugin's database. This occurs when the plugin fails to properly sanitize and escape user input for Product Option fields, allowing attackers to inject arbitrary web scripts that will execute when an administrator views the entry details. As a result, unauthenticated attackers can inject malicious code that will execute when an administrator accesses the entry details page, potentially leading to further exploitation.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.