Stored Cross-Site Scripting in Magic Conversation for Gravity Forms by WordPress
CVE-2026-1396
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 April 2026
What is CVE-2026-1396?
The Magic Conversation For Gravity Forms plugin for WordPress is affected by a Stored Cross-Site Scripting vulnerability. This issue arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'magic-conversation' shortcode. It allows authenticated attackers with contributor-level access or above to inject arbitrary web scripts. These scripts execute automatically whenever users access an affected page, posing serious security risks.
Affected Version(s)
Magic Conversation For Gravity Forms 0 <= 3.0.97