CVE-2026-3492Disclosure

LOWCVSS 6.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure involving missing authorization on the `create_from_template` AJAX endpoint (allowing any authenticated user to create forms), insufficient input sanitization (`sanitize_text_field()` preserves single quotes), and missing output escaping when the form title is rendered in the Form Switcher dropdown (`title` attribute constructed without `esc_attr()`, and JavaScript `saferHtml` utility only escapes `&`, `<`, `>` but not quotes). This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary JavaScript that executes when an Administrator searches in the Form Switcher dropdown in the Form Editor.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-15); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-15: 1Mentions · 2026-07-22: 1Active Exploitation · 2026-07-22: 1Technical Details · 2026-03-15: 103-1507-22
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-151
Disclosure1
2026-07-221
Active Exploitation1
Full discourse2 posts
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-34291 Langflow Origin Validation Error Vulnerability CVE-2026-3492 @CISACyber

    Post summary

    CISA has added CVE-2025-34291 and CVE-2026-3492 to its Known Exploited Vulnerabilities catalog, indicating evidence of active exploitation, but no proof‑of‑concept, exploit code, patch, or detailed vulnerability information is provided.

    0000050
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3492 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.9.28.1. This is due to a compound failure in… https://www.cve.org/CVERecord?id=CVE-2026-3492

    Post summary

    The post announces that Gravity Forms plugin versions up to 2.9.28.1 are vulnerable to stored XSS.

    00000144
    56.7K followersView on X

Explore more