WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection
CVE-2023-28782
8.3HIGH
What is CVE-2023-28782?
A deserialization of untrusted data vulnerability exists in Gravity Forms by Rocketgenius Inc., impacting all versions up to 2.7.3. This flaw could allow an attacker to exploit PHP object injection risks, potentially leading to unauthorized access or control over the application. It is vital for users and administrators of the affected versions to assess their systems for this vulnerability and apply any available patches or updates to mitigate risks.
Affected Version(s)
Gravity Forms <= 2.7.3