CVE · High

CVE-2026-5111 — Gravity Forms [gravityforms] < 2.10.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5111 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01

CVE-2026-5111

A security flaw exists in Gravity Forms plugin versions up to 2.10.0, allowing malicious scripts to be injected into WordPress sites via Hidden Product field values within Repeater fields. This vulnerability arises from inadequate input verification and output sanitization of these field values, which are later displayed without proper protection. As a result, unauthenticated attackers can embed arbitrary web code that will run whenever an administrator views the entry details.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.