CVE-2026-5109Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because the state validation function accepts submitted values where the wp_kses()-sanitized version matches a legitimate option value, but then stores the raw unsanitized value in the database. When administrators view entry details via the Order Summary section, the option_label is output directly without escaping (view-order-summary.php line 32), executing the injected JavaScript. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entry data that will execute whenever an administrator accesses the entry details page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-02: 4Technical Details · 2026-05-02: 405-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5109 Stored Cross-Site Scripting in Gravity Forms Plugin for WordPress Up to 2.10.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5109

    Post summary

    This entry announces a stored XSS vulnerability in Gravity Forms plugin versions up to 2.10.0, providing basic technical details but no PoC, exploit code, patch, or evidence of active exploitation.

    0001059
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5109 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and o… https://www.cve.org/CVERecord?id=CVE-2026-5109

    Post summary

    The Gravity Forms plugin for WordPress contains a stored XSS vulnerability (CVE‑2026‑5109) affecting versions up to 2.10.0, as noted by the CVE record, with no mention of PoC, exploit code, patches, or active exploitation.

    00010198
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5109 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and o… https://www.cve.org/CVERecord?id=CVE-2026-5109 ----- Traducción: CVE-2026-5109 El … http://infoflow.cloud`

    Post summary

    CVE-2026-5109 exposes a stored XSS vulnerability in Gravity Forms up to version 2.10.0, as noted in the CVE record link, with no mentions of exploitation, patches, or PoC.

    0000037
    75 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5109 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.1… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5109 #WordPress #CyberSecurity #InfoSec

    Post summary

    The tweet announces a high‑severity stored XSS vulnerability (CVE‑2026‑5109) in Gravity Forms (v≤2.1) with a CVSS score of 7.2, but does not provide PoC, exploit code, active exploitation, or patch information.

    0000041
    458 followersView on X

Explore more