CVE Database /
CVE-2026-5111
CVE · High
CVE-2026-5111 — Gravity Forms [gravityforms] < 2.10.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-5111
|
Gravity Forms [gravityforms] < 2.10.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
High
7.2
|
< 2.10.1
|
2.10.1 |
2026-05-01 |
—
|
CVE-2026-5111
A security flaw exists in Gravity Forms plugin versions up to 2.10.0, allowing malicious scripts to be injected into WordPress sites via Hidden Product field values within Repeater fields. This vulnerability arises from inadequate input verification and output sanitization of these field values, which are later displayed without proper protection. As a result, unauthenticated attackers can embed arbitrary web code that will run whenever an administrator views the entry details.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings