Impact
Gravity Forms, a widely used WordPress form plugin, allows an attacker to store arbitrary scripts in the post body field value. The application fails to fully sanitize user input, meaning malicious code enters the post and is re‑parsed on the client side when a page is viewed. Once stored, any user who opens the affected page will have the malicious script executed in their browser.
Affected Systems
The vulnerability is present in all Gravity Forms releases up to and including version 2.10.5. WordPress sites that have this plugin installed and have enabled the post body field can be impacted.
Risk and Exploitability
The vulnerability has a CVSS v3 score of 7.2 and is listed as not being in the CISA KEV catalog. Attackers need only to craft a form submission containing malicious code; no authentication is required. Exploitation is likely to be observed if the plugin is enabled on a publicly reachable site, though no EPSS data is available. The stored nature of the flaw means the effect persists until the content is removed or the plugin is updated.
OpenCVE Enrichment