Reflected Cross-Site Scripting Vulnerability in Daman Jeet Real Time Validation Plugin for Gravity Forms
CVE-2025-48329

7.1HIGH

What is CVE-2025-48329?

A vulnerability in the Daman Jeet Real Time Validation plugin for Gravity Forms allows an attacker to exploit reflected Cross-site Scripting (XSS) issues. This flaw arises from improper handling of user inputs during web page generation, potentially enabling attackers to inject malicious scripts. These scripts could execute in the context of unsuspecting users' browsers, leading to unauthorized actions or data exposure if exploited. Users should update the plugin to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Real Time Validation for Gravity Forms <= 1.7.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.