PLUGIN SECURITY

Is Gravityforms safe?

Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.

What this plugin does

  • Slug: gravityforms
  • Author: DannyvanHolten
  • 30000+ active installs
  • 84/100 rating (14 reviews on wordpress.org)
  • 592573 all-time downloads
  • On WordPress.org since 2017-04-07

acfadvanced custom fieldsformgravity formssayhellogmbh

Maintenance status

  • Latest known version: 1.3.10
  • Last updated: 2025-12-02 5:20pm GMT
  • Tested up to WordPress: 6.9.0

Known vulnerabilities

20 known CVEs on file for Gravityforms.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12997 Gravity Forms [gravityforms] < 2.10.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.10.5 2.10.5 2026-07-15 ⚠ update needed
CVE-2026-19513 Gravity Forms [gravityforms] < 3.0.3 Unrestricted Upload of File with Dangerous Type High 8.1 < 3.0.3 3.0.3 2026-07-15 ⚠ update needed
CVE-2026-48866 Gravity Forms [gravityforms] < 2.10.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.6 < 2.10.1 2.10.1 2026-06-01 ⚠ update needed
CVE-2026-5111 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01 ⚠ update needed
CVE-2026-5110 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01 ⚠ update needed
CVE-2026-5113 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01 ⚠ update needed
CVE-2026-5112 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01 ⚠ update needed
CVE-2026-5109 Gravity Forms [gravityforms] < 2.10.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.10.1 2.10.1 2026-05-01 ⚠ update needed
+ 35 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-13407 Gravity Forms [gravityforms] < 2.9.23.1 Unrestricted Upload of File with Dangerous Type Medium 6.8 < 2.9.23.1 2.9.23.1 2025-12-03 ⚠ update needed
CVE-2025-12974 Gravity Forms [gravityforms] < 2.9.22 Unrestricted Upload of File with Dangerous Type High 8.1 < 2.9.22 2.9.22 2025-11-17 ⚠ update needed
CVE-2025-12352 Gravity Forms [gravityforms] < 2.9.21 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 2.9.21 2.9.21 2025-11-06 ⚠ update needed
CVE-2024-13377 Gravity Forms [gravityforms] < 2.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 2.9.2 2.9.2 2025-01-16 ⚠ update needed
CVE-2024-13378 Gravity Forms [gravityforms] < 2.9.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.9.2 2.9.2 2025-01-16 ⚠ update needed
Gravity Forms [gravityforms] < 2.0.7 Unknown < 2.0.7 2.0.7 2023-10-13 ⚠ update needed
CVE-2023-2701 Gravity Forms [gravityforms] < 2.7.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.7.5 2.7.5 2023-06-21 ⚠ update needed
Gravity Forms [gravityforms] < 1.8.20 Unknown < 1.8.20 1.8.20 2023-06-17 ⚠ update needed
CVE-2023-28782 Gravity Forms [gravityforms] < 2.7.4 Deserialization of Untrusted Data High 8.3 < 2.7.4 2.7.4 2023-05-29 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.7 Unknown < 1.9.7 1.9.7 2023-04-20 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.3.6 Unknown < 1.9.3.6 1.9.3.6 2023-03-17 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.16 Unknown < 1.9.16 1.9.16 2023-03-01 ⚠ update needed
CVE-2020-13764 Gravity Forms [gravityforms] < 2.4.9 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 2.4.9 2.4.9 2019-05-08 ⚠ update needed
Gravity Forms [gravityforms] < 2.0.7 Unknown < 2.0.7 2.0.7 2016-09-07 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.16 Unknown < 1.9.16 1.9.16 2016-03-01 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.7 Unknown < 1.9.7 1.9.7 2015-04-20 ⚠ update needed
Gravity Forms [gravityforms] < 1.8.20 Unknown < 1.8.20 1.8.20 2015-02-26 ⚠ update needed
CVE-2015-2260 Gravity Forms [gravityforms] >= 1.8 - <= 1.9.3.5 Unknown 1.8–1.9.3.5 1.9.3.5 0000-00-00 ⚠ update needed
Gravity Forms [gravityforms] < 2.9.31 Medium 6.1 < 2.9.31 2.9.31 0000-00-00 ⚠ update needed
Gravity Forms [gravityforms] < 2.9.31 Medium 4.7 < 2.9.31 2.9.31 0000-00-00 ⚠ update needed
Gravity Forms [gravityforms] < 2.9.29 Unknown < 2.9.29 2.9.29 0000-00-00 ⚠ update needed
Gravity Forms [gravityforms] < 2.0.7 Unknown < 2.0.7 2.0.7 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.16 Unknown < 1.9.16 1.9.16 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.7 Unknown < 1.9.7 1.9.7 ⚠ update needed
Gravity Forms [gravityforms] < 1.9.3.6 Unknown < 1.9.3.6 1.9.3.6 ⚠ update needed
Gravity Forms [gravityforms] < 1.8.20 Unknown < 1.8.20 1.8.20 ⚠ update needed
Gravity Forms <= 1.8.19 - Arbitrary File Upload Unknown < 1.8.20 1.8.20 ⚠ update needed
Gravity Forms 1.8 <= 1.9.3.5 - Authenticated Blind SQL Injection Unknown < 1.9.3.6 1.9.3.6 ⚠ update needed
Gravity Forms <= 1.9.6 - Cross-Site Scripting (XSS) Unknown < 1.9.7 1.9.7 ⚠ update needed
Gravity Forms < 1.9.16 - Authenticated Reflected Cross-Site Scripting (XSS) Unknown < 1.9.16 1.9.16 ⚠ update needed
Gravity Forms < 2.0.7 - Authenticated Blind Cross-Site Scripting (XSS) Unknown < 2.0.7 2.0.7 ⚠ update needed
GravityForms 2.9.11.1 / 2.9.12 - Malware Compromise Unknown < 2.9.13 2.9.13 ⚠ update needed
CVE-2026-3492 Gravity Forms < 2.9.29 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title Unknown < 2.9.29 2.9.29 ⚠ update needed
CVE-2026-4406 Gravity Forms < 2.9.31 - Reflected Cross-Site Scripting via 'form_ids' Parameter Unknown < 2.9.31 2.9.31 ⚠ update needed
CVE-2026-4394 Gravity Forms < 2.9.31 - Unauthenticated Stored Cross-Site Scripting via Credit Card 'Card Type' Sub-Field Unknown < 2.9.31 2.9.31 ⚠ update needed

How to fix it

Keep Gravityforms updated — 1.3.10 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.