
CVE-2026-5112 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient … https://www.cve.org/CVERecord?id=CVE-2026-5112
Post summary
The excerpt announces that Gravity Forms plugin versions up to 2.10.0 are vulnerable to unauthenticated stored XSS, providing technical details but no PoC, exploit, patch, or active exploitation evidence.


