Executive brief
The Signature Add-On for Gravity Forms is a WordPress plugin that enables digital signature collection in forms. A misconfigured access control flaw allows subscribers and other low-privilege users to access pages and perform actions they should not be authorized for, potentially exposing sensitive form data and allowing unauthorized modifications.
Technical details
This broken access control vulnerability in Signature Add-On for Gravity Forms (affecting versions <= 1.8.6) stems from inadequate authorization checks on sensitive operations. An attacker with subscriber-level privileges can bypass access control restrictions to view or manipulate protected form data and administrative functions. The vulnerability requires a valid user account (subscriber privilege or higher) on the affected WordPress installation. The flaw was patched in version 1.8.7; administrators should update immediately to mitigate unauthorized data access.
Affected products
- WP E-Signature Signature Add-On for Gravity Forms through 1.8.6
Timeline
- 2025-12-31: disclosed: Published by Patchstack
- 2025-12-31: patched: Fixed in version 1.8.7
- 2025-09-24: other: Initially reported by Nabil Irawan