Stored Cross-Site Scripting in Gravity Forms Plugin for WordPress
CVE-2026-4394

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 April 2026

What is CVE-2026-4394?

The Gravity Forms plugin for WordPress contains a vulnerability in its Credit Card field that allows for Stored Cross-Site Scripting (XSS). This occurs when the 'Card Type' sub-field is manipulated through the get_value_entry_detail() method in the GF_Field_CreditCard class. The system does not escape the card type value and accepts unsanitized input, which can lead to the execution of arbitrary web scripts when an administrator views the form submission in the dashboard. This vulnerability poses significant risks as it can facilitate unauthorized actions on the site.

Affected Version(s)

Gravity Forms 0 <= 2.9.30

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

tadokun
.