THREAT OPS › Threat News › [NVD] CVE-2026-12477 (MEDIUM 4.4) — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenti
[NVD] CVE-2026-12477 (MEDIUM 4.4) — The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenti
CVE-2026-12477 CVSS: 4.4 MEDIUM Published: 2026-08-16T05:16:45.810
The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 5.26 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and a
Indicators of compromise
- CVE-2026-12477cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-12477