WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection
CVE-2023-28782

8.3HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 December 2023

Summary

A deserialization of untrusted data vulnerability exists in Gravity Forms by Rocketgenius Inc., impacting all versions up to 2.7.3. This flaw could allow an attacker to exploit PHP object injection risks, potentially leading to unauthorized access or control over the application. It is vital for users and administrators of the affected versions to assess their systems for this vulnerability and apply any available patches or updates to mitigate risks.

Affected Version(s)

Gravity Forms <= 2.7.3

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.