CVE-2026-5113Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by wp_kses(), combined with insufficient output escaping. The state validation logic creates two hashes (raw input and wp_kses-sanitized input) and only fails validation if BOTH hashes don't match the original state. When an attacker injects XSS payloads using tags stripped by wp_kses() (like <svg>), the sanitized hash matches while the malicious raw value is preserved and saved to the database. When administrators view the Entries List page, the stored malicious consent label is retrieved and output without escaping, causing the XSS payload to execute. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in entries that will execute whenever an authenticated administrator accesses the entries list page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Technical Details · 2026-05-02: 305-02
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5113 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due … https://www.cve.org/CVERecord?id=CVE-2026-5113 ----- Traducción: CVE-2026-5113 El … http://infoflow.cloud`

    Post summary

    The entry announces CVE‑2026‑5113, a stored XSS vulnerability in Gravity Forms, focusing solely on the disclosure and technical description, without mentioning proof of concept, exploitation, or mitigations.

    0001039
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5113 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due … https://www.cve.org/CVERecord?id=CVE-2026-5113

    Post summary

    The post announces a stored XSS vulnerability in Gravity Forms Plugin (CVE‑2026‑5113) targeting hidden input fields in older versions up to 2.10.0.

    00010235
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5113 Stored Cross-Site Scripting in Gravity Forms WordPress Plugin Versions Up to 2.10.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5113

    Post summary

    The text announces CVE-2026-5113, a stored XSS flaw in Gravity Forms WordPress plugin versions up to 2.10.0, providing the CVE identifier and a reference link but no exploit or mitigation details.

    0000055
    4.0K followersView on X

Explore more