Input validation vulnerability in Gravity Forms 2.9.1.3

A plugin called Gravity Forms for WordPress has a security issue that allows hackers to insert harmful code into certain pages. This can happen in versions 2.9.0.1 through 2.9.1.3 because the plugin does not properly clean and protect the information that is entered. This allows attackers to manipulate the page and potentially harm users. The attack only works in the Chrome web browser and requires the user to directly access a specific type of file.

Detected in:

Gravity Forms fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.