Junglewise Threat Intelligence

CVE-2026-4406: Gravity Forms Reflected XSS in gform_get_config AJAX action

CVE-2026-4406 · Severity: medium · CVSS 4.7 · Published 2026-04-08

Vendors: Gravity Forms.

Executive brief

Gravity Forms is a popular WordPress plugin used to create and manage web forms. A security vulnerability allows unauthenticated attackers to inject malicious scripts into a web page if they can trick a user into clicking a specific link. While this cannot be used to directly steal data from logged-in users, it can be used to alter the appearance of the page or redirect visitors to malicious sites.

Technical details

The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw within the `gform_get_config` AJAX action. The root cause is the `GFCommon::send_json()` method, which outputs JSON-encoded data wrapped in HTML comment delimiters using `echo` and `wp_die()`, causing the browser to interpret the response as `text/html` instead of `application/json`. Because `wp_json_encode()` does not escape angle brackets, an attacker can inject script tags into the `form_ids` array. Exploitation requires a valid `config_nonce`, which is publicly accessible on any page rendering a form and remains valid for 12 hours. An unauthenticated attacker can execute arbitrary JavaScript in the context of a victim's browser via a crafted link, though the impact is limited to unauthenticated sessions. The issue was addressed in version 2.9.31.

Affected products

  • Gravity Forms Gravity Forms <= 2.9.30

Timeline

  • 2026-03-19: other: Last vulnerable version (2.9.30) released
  • 2026-04-02: patched: Fixed in version 2.9.31
  • 2026-04-08: disclosed: CVE published

References