Junglewise Threat Intelligence

CVE-2026-1396: Magic Plugins Magic Conversation For Gravity Forms Stored XSS in shortcode

CVE-2026-1396 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

The Magic Conversation For Gravity Forms plugin for WordPress, which adds interactive conversational features to web forms, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The Magic Conversation For Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'magic-conversation' shortcode. This vulnerability is classified as CWE-79. An authenticated attacker with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into pages. These scripts will execute in the context of a user's browser whenever they access the affected page. The issue exists in all versions up to 3.0.97; a changeset (3482359) indicates that a fix has been developed.

Affected products

  • magicplugins Magic Conversation For Gravity Forms up to, and including, 3.0.97

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References