Executive brief
Gravity Forms is a popular WordPress plugin used to create and manage web forms. A security vulnerability allows unauthenticated attackers to inject malicious scripts into a web page if they can trick a user into clicking a specific link. While this cannot be used to directly steal data from logged-in users, it can be used to alter the appearance of the page or redirect visitors to malicious sites.
Technical details
The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw within the `gform_get_config` AJAX action. The root cause is the `GFCommon::send_json()` method, which outputs JSON-encoded data wrapped in HTML comment delimiters using `echo` and `wp_die()`, causing the browser to interpret the response as `text/html` instead of `application/json`. Because `wp_json_encode()` does not escape angle brackets, an attacker can inject script tags into the `form_ids` array. Exploitation requires a valid `config_nonce`, which is publicly accessible on any page rendering a form and remains valid for 12 hours. An unauthenticated attacker can execute arbitrary JavaScript in the context of a victim's browser via a crafted link, though the impact is limited to unauthenticated sessions. The issue was addressed in version 2.9.31.
Affected products
- Gravity Forms Gravity Forms <= 2.9.30
Timeline
- 2026-03-19: other: Last vulnerable version (2.9.30) released
- 2026-04-02: patched: Fixed in version 2.9.31
- 2026-04-08: disclosed: CVE published
References
- https://docs.gravityforms.com/gravityforms-change-log/
- https://plugins.trac.wordpress.org/browser/gravityforms/trunk/common.php
- https://plugins.trac.wordpress.org/browser/gravityforms/trunk/includes/config/class-gf-config-collection.php
- https://plugins.trac.wordpress.org/browser/gravityforms/trunk/includes/config/class-gf-config-service-provider.php
- https://plugins.trac.wordpress.org/browser/gravityforms/trunk/includes/config/items/class-gf-config-global.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4126d452-65a9-48f5-a3f5-5be1b8fff80c?source=cve