MEDIUM4.8
GHSA-wmh7-782f-xfw5
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability
Quick fix
GHSA-wmh7-782f-xfw5 — wp-premium/gravityforms: upgrade to the fixed version with the command below.
composer require wp-premium/gravityforms:^2.4.21Details
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/wp-premium/gravityforms
Introduced in:
2.4Fixed in: 2.4.21Fix
composer require wp-premium/gravityforms:^2.4.21