Junglewise Threat Intelligence

CVE-2026-57665: GravityKit GravityView IDOR in WordPress plugin

CVE-2026-57665 · Severity: medium · CVSS 5.3 · Published 2026-06-26

Executive brief

GravityView is a WordPress plugin used to display and manage data collected through Gravity Forms. A security flaw in versions 3.0.0 and earlier allows unauthorized individuals to access data records they should not be able to see. This could lead to the exposure of sensitive information submitted by users through website forms.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the GravityKit GravityView plugin for WordPress (versions <= 3.0.0). The flaw is categorized as CWE-639, where the application fails to properly validate authorization when a user-controlled input is used to access a database object. An unauthenticated remote attacker can exploit this by manipulating identifiers in requests to view sensitive form entry data that should be restricted. The issue is resolved in version 3.0.1.

Affected products

  • GravityKit GravityView <= 3.0.0

Timeline

  • 2026-06-21: other: Reported by Austin Ginder
  • 2026-06-26: advisory: Published by Patchstack
  • 2026-06-26: patched: Version 3.0.1 released

References