Stored Cross-Site Scripting Vulnerability in Gravity Forms Plugin for WordPress
CVE-2026-16649
7.2HIGH
What is CVE-2026-16649?
The Gravity Forms plugin for WordPress is susceptible to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping in the Post Body Field Value. An unauthenticated attacker can exploit this vulnerability to inject arbitrary web scripts into pages, which will execute when a user accesses the compromised page. This vulnerability is particularly dangerous because it can evade save-time sanitization processes. The wp_kses_post function allows certain HTML tags and attributes, and due to the handling of the aria-label value in client-side scripts, malicious event-handler attributes may remain executable even after other script elements are stripped.
Affected Version(s)
Gravity Forms 0 <= 2.10.5