CVE-2026-5110Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a Repeater field. When SingleProduct fields are nested within Repeater fields, the validation flow bypasses the state validation mechanism (failed_state_validation()) that would normally prevent tampering with field values. The validate_subfield() method only calls the field's validate() method, which for SingleProduct fields only validates the quantity field and does not check the product name field for tampering. As a result, an attacker can inject arbitrary HTML and JavaScript into the product name field (input .1). This malicious input is then saved to the database without sanitization because sanitize_entry_value() returns raw values when HTML is not expected for the field type. When an administrator views the entry in wp-admin/admin.php?page=gf_entries, the get_value_entry_detail() method outputs the product name without escaping, causing the stored XSS payload to execute in the administrator's browser. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator accesses an entry containing the malicious payload.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-05-02: 4Technical Details · 2026-05-02: 405-02
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5110 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient … https://www.cve.org/CVERecord?id=CVE-2026-5110 ----- Traducción: CVE-2026-5110 El … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑5110 as an unauthenticated stored XSS flaw in Gravity Forms up to version 2.10.0, but does not provide PoC, exploit, or patch details.

    0001047
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5110 Unauthenticated Stored Cross-Site Scripting in Gravity Forms WordPress Plugin 2.10.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5110

    Post summary

    The text announces the newly discovered CVE-2026-5110, an unauthenticated stored XSS vulnerability in Gravity Forms WordPress Plugin 2.10.0, giving limited technical details but no evidence of exploitation or resolution.

    0000067
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5110 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient … https://www.cve.org/CVERecord?id=CVE-2026-5110

    Post summary

    The post announces a new CVE‑2026‑5110: an unauthenticated stored XSS vulnerability in Gravity Forms plugin versions up to 2.10.0, providing basic technical details but no PoC, exploit code, patch, or exploitation evidence.

    00000188
    57.4K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5110 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to a… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5110 #WordPress #CyberSecurity #InfoSec

    Post summary

    A new high‑severity XSS flaw (CVE‑2026‑5110) in Gravity Forms for WordPress is disclosed with CVSS 7.2, but no PoC, exploit, or patch details are provided.

    0000050
    458 followersView on X

Explore more