{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/repeater-fields-for-gravity-forms--3.0.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:repeater_fields_for_gravity_forms_project:repeater_fields_for_gravity_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-84293"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Repeater Fields for Gravity Forms (\u003c= 3.0.4)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Repeater Fields for Gravity Forms plugin for WordPress (versions up to and including 3.0.4) contains a vulnerability to Stored Cross-Site Scripting (XSS). The flaw stems from insufficient input sanitization and output escaping within multi-input sub-fields such as Name, Address, and Checkbox fields. Unlike scalar single-input fields, which are protected by esc_html() in version 3.0.4, these complex sub-fields allow an unauthenticated attacker to inject malicious scripts into the application. Once stored, these scripts execute within the context of a user's browser whenever the affected page is loaded. This poses a significant risk for account takeover or unauthorized actions if an administrative user views the injected content.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to inject malicious web scripts into WordPress pages. If these scripts are executed in the context of an administrator's session, attackers could potentially perform unauthorized administrative actions, steal session cookies, or redirect users to malicious domains.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Repeater Fields for Gravity Forms plugin to the latest version beyond 3.0.4 to ensure proper output escaping is applied to all sub-field types. Monitor server-side web application logs for POST requests containing script tags or JavaScript event handlers directed at endpoints processing Gravity Forms submissions.\u003c/p\u003e\n","date_modified":"2026-09-09T05:51:41Z","date_published":"2026-09-09T05:51:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84293/","summary":"The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored XSS due to improper sanitization of multi-input sub-fields, allowing unauthenticated attackers to execute arbitrary JavaScript.","title":"Stored XSS in Repeater Fields for Gravity Forms Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84293/"}],"language":"en","title":"CraftedSignal Threat Feed - Repeater Fields for Gravity Forms (\u003c= 3.0.4)","version":"https://jsonfeed.org/version/1.1"}