Stored Cross-Site Scripting Vulnerability in Gravity Forms Plugin by WordPress
CVE-2026-84293
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-84293?
The Repeater Fields extension for the Gravity Forms plugin is susceptible to stored cross-site scripting due to inadequate input sanitization and output escaping. This vulnerability specifically targets repeated multi-input sub-field values, enabling unauthenticated attackers to inject malicious scripts that execute upon user access to affected web pages. Notably, single-input fields are protected against such attacks, making this issue particularly concerning for fields like Name and Address.
Affected Version(s)
Repeater Fields for Gravity Forms 0 <= 3.0.4