PLUGIN SECURITY
Is Gravityforms safe?
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
What this plugin does
- Slug:
gravityforms - Author: DannyvanHolten
- 30000+ active installs
- 84/100 rating (14 reviews on wordpress.org)
- 592573 all-time downloads
- On WordPress.org since 2017-04-07
acfadvanced custom fieldsformgravity formssayhellogmbh
Maintenance status
- Latest known version: 1.3.10
- Last updated: 2025-12-02 5:20pm GMT
- Tested up to WordPress: 6.9.0
Known vulnerabilities
20 known CVEs on file for Gravityforms.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-12997 | Gravity Forms [gravityforms] < 2.10.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | High 7.5 | < 2.10.5 | 2.10.5 | 2026-07-15 | ⚠ update needed |
| CVE-2026-19513 | Gravity Forms [gravityforms] < 3.0.3 | Unrestricted Upload of File with Dangerous Type | High 8.1 | < 3.0.3 | 3.0.3 | 2026-07-15 | ⚠ update needed |
| CVE-2026-48866 | Gravity Forms [gravityforms] < 2.10.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Critical 9.6 | < 2.10.1 | 2.10.1 | 2026-06-01 | ⚠ update needed |
| CVE-2026-5111 | Gravity Forms [gravityforms] < 2.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.10.1 | 2.10.1 | 2026-05-01 | ⚠ update needed |
| CVE-2026-5110 | Gravity Forms [gravityforms] < 2.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.10.1 | 2.10.1 | 2026-05-01 | ⚠ update needed |
| CVE-2026-5113 | Gravity Forms [gravityforms] < 2.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.10.1 | 2.10.1 | 2026-05-01 | ⚠ update needed |
| CVE-2026-5112 | Gravity Forms [gravityforms] < 2.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.10.1 | 2.10.1 | 2026-05-01 | ⚠ update needed |
| CVE-2026-5109 | Gravity Forms [gravityforms] < 2.10.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.10.1 | 2.10.1 | 2026-05-01 | ⚠ update needed |
+ 35 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2025-13407 | Gravity Forms [gravityforms] < 2.9.23.1 | Unrestricted Upload of File with Dangerous Type | Medium 6.8 | < 2.9.23.1 | 2.9.23.1 | 2025-12-03 | ⚠ update needed |
| CVE-2025-12974 | Gravity Forms [gravityforms] < 2.9.22 | Unrestricted Upload of File with Dangerous Type | High 8.1 | < 2.9.22 | 2.9.22 | 2025-11-17 | ⚠ update needed |
| CVE-2025-12352 | Gravity Forms [gravityforms] < 2.9.21 | Unrestricted Upload of File with Dangerous Type | Critical 9.8 | < 2.9.21 | 2.9.21 | 2025-11-06 | ⚠ update needed |
| CVE-2024-13377 | Gravity Forms [gravityforms] < 2.9.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.2 | < 2.9.2 | 2.9.2 | 2025-01-16 | ⚠ update needed |
| CVE-2024-13378 | Gravity Forms [gravityforms] < 2.9.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.9.2 | 2.9.2 | 2025-01-16 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 2.0.7 | — | Unknown | < 2.0.7 | 2.0.7 | 2023-10-13 | ⚠ update needed |
| CVE-2023-2701 | Gravity Forms [gravityforms] < 2.7.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.7.5 | 2.7.5 | 2023-06-21 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.8.20 | — | Unknown | < 1.8.20 | 1.8.20 | 2023-06-17 | ⚠ update needed |
| CVE-2023-28782 | Gravity Forms [gravityforms] < 2.7.4 | Deserialization of Untrusted Data | High 8.3 | < 2.7.4 | 2.7.4 | 2023-05-29 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.7 | — | Unknown | < 1.9.7 | 1.9.7 | 2023-04-20 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.3.6 | — | Unknown | < 1.9.3.6 | 1.9.3.6 | 2023-03-17 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.16 | — | Unknown | < 1.9.16 | 1.9.16 | 2023-03-01 | ⚠ update needed |
| CVE-2020-13764 | Gravity Forms [gravityforms] < 2.4.9 | Exposure of Sensitive Information to an Unauthorized Actor | High 7.5 | < 2.4.9 | 2.4.9 | 2019-05-08 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 2.0.7 | — | Unknown | < 2.0.7 | 2.0.7 | 2016-09-07 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.16 | — | Unknown | < 1.9.16 | 1.9.16 | 2016-03-01 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.7 | — | Unknown | < 1.9.7 | 1.9.7 | 2015-04-20 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.8.20 | — | Unknown | < 1.8.20 | 1.8.20 | 2015-02-26 | ⚠ update needed |
| CVE-2015-2260 | Gravity Forms [gravityforms] >= 1.8 - <= 1.9.3.5 | — | Unknown | 1.8–1.9.3.5 | 1.9.3.5 | 0000-00-00 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 2.9.31 | — | Medium 6.1 | < 2.9.31 | 2.9.31 | 0000-00-00 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 2.9.31 | — | Medium 4.7 | < 2.9.31 | 2.9.31 | 0000-00-00 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 2.9.29 | — | Unknown | < 2.9.29 | 2.9.29 | 0000-00-00 | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 2.0.7 | — | Unknown | < 2.0.7 | 2.0.7 | — | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.16 | — | Unknown | < 1.9.16 | 1.9.16 | — | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.7 | — | Unknown | < 1.9.7 | 1.9.7 | — | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.9.3.6 | — | Unknown | < 1.9.3.6 | 1.9.3.6 | — | ⚠ update needed |
| — | Gravity Forms [gravityforms] < 1.8.20 | — | Unknown | < 1.8.20 | 1.8.20 | — | ⚠ update needed |
| — | Gravity Forms <= 1.8.19 - Arbitrary File Upload | — | Unknown | < 1.8.20 | 1.8.20 | — | ⚠ update needed |
| — | Gravity Forms 1.8 <= 1.9.3.5 - Authenticated Blind SQL Injection | — | Unknown | < 1.9.3.6 | 1.9.3.6 | — | ⚠ update needed |
| — | Gravity Forms <= 1.9.6 - Cross-Site Scripting (XSS) | — | Unknown | < 1.9.7 | 1.9.7 | — | ⚠ update needed |
| — | Gravity Forms < 1.9.16 - Authenticated Reflected Cross-Site Scripting (XSS) | — | Unknown | < 1.9.16 | 1.9.16 | — | ⚠ update needed |
| — | Gravity Forms < 2.0.7 - Authenticated Blind Cross-Site Scripting (XSS) | — | Unknown | < 2.0.7 | 2.0.7 | — | ⚠ update needed |
| — | GravityForms 2.9.11.1 / 2.9.12 - Malware Compromise | — | Unknown | < 2.9.13 | 2.9.13 | — | ⚠ update needed |
| CVE-2026-3492 | Gravity Forms < 2.9.29 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title | — | Unknown | < 2.9.29 | 2.9.29 | — | ⚠ update needed |
| CVE-2026-4406 | Gravity Forms < 2.9.31 - Reflected Cross-Site Scripting via 'form_ids' Parameter | — | Unknown | < 2.9.31 | 2.9.31 | — | ⚠ update needed |
| CVE-2026-4394 | Gravity Forms < 2.9.31 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field | — | Unknown | < 2.9.31 | 2.9.31 | — | ⚠ update needed |
How to fix it
Keep Gravityforms updated — 1.3.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Advanced Custom Fields (ACF®) — 2000000+ active installs — 90/100 (1438) — max PHP 8.4
- ACF Content Analysis for Yoast SEO — 100000+ active installs — 82/100 (35) — max PHP 8.4
- Advanced Custom Fields: Extended — 100000+ active installs — 96/100 (132) — max PHP <8.0
- Advanced Custom Fields: Font Awesome Field — 90000+ active installs — 98/100 (36) — max PHP 8.4
- ACF Photo Gallery Field — 60000+ active installs — 80/100 (29)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.