VDB
Sign up
MEDIUM5.4

GHSA-fcj2-rxqc-294c

Gravity Forms stored HTML injection vulnerability

Quick fix

GHSA-fcj2-rxqc-294c — wp-premium/gravityforms: upgrade to the fixed version with the command below.

composer require wp-premium/gravityforms:^2.4.21

Details

Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/wp-premium/gravityforms
Introduced in: 0Fixed in: 2.4.21
Fixcomposer require wp-premium/gravityforms:^2.4.21

References