VDB
Sign up
HIGH7.5

GHSA-m983-q76g-cwpq

Gravity Forms plugin leak hashed passwords

Quick fix

GHSA-m983-q76g-cwpq — wp-premium/gravityforms: upgrade to the fixed version with the command below.

composer require wp-premium/gravityforms:^2.4.9

Details

common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a `$current_user->get($property)` call.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/wp-premium/gravityforms
Introduced in: 0Fixed in: 2.4.9
Fixcomposer require wp-premium/gravityforms:^2.4.9

References