THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-12477 (MEDIUM 4.4) — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenti

[NVD] CVE-2026-12477 (MEDIUM 4.4) — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenti

mednvdPublished 2026-08-16

CVE-2026-12477 CVSS: 4.4 MEDIUM Published: 2026-08-16T05:16:45.810

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12477