Input validation vulnerability in Gravityforms 2.0.6.5

WordPress Plugin Gravity Forms is prone to a security issue called a cross-site scripting vulnerability. This means it doesn’t protect user-supplied input properly. An attacker can use this to run malicious script code in the browser of a person viewing the affected site. This script code can steal authentication credentials, like passwords, and be used for other attacks. Versions of Gravity Forms from 2.0.6.5 and earlier may be affected.

Detected in:

Gravity Forms fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.