The Gravity Forms WordPress plugin before 2.7.5 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high-privileged users such as admin.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-10-30T13:59:16.682Z
Reserved: 2023-05-15T09:55:25.578Z
Link: CVE-2023-2701

Updated: 2024-08-02T06:33:05.309Z

Status : Modified
Published: 2023-07-17T14:15:10.097
Modified: 2024-11-21T07:59:06.923
Link: CVE-2023-2701

No data.