VDB
Sign up
MEDIUM5.4

GHSA-pjv5-v9gv-3679

Gravity Forms stored Cross-Site Scripting (XSS) vulnerability in the survey feature

Quick fix

GHSA-pjv5-v9gv-3679 — wp-premium/gravityforms: upgrade to the fixed version with the command below.

composer require wp-premium/gravityforms:^2.4.21

Details

A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/wp-premium/gravityforms
Introduced in: 2.4Fixed in: 2.4.21
Fixcomposer require wp-premium/gravityforms:^2.4.21

References