<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Repeater Fields for Gravity Forms (&lt;= 3.0.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/repeater-fields-for-gravity-forms--3.0.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 05:51:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/repeater-fields-for-gravity-forms--3.0.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Repeater Fields for Gravity Forms Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84293/</link><pubDate>Wed, 09 Sep 2026 05:51:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-84293/</guid><description>The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored XSS due to improper sanitization of multi-input sub-fields, allowing unauthenticated attackers to execute arbitrary JavaScript.</description><content:encoded><![CDATA[<p>The Repeater Fields for Gravity Forms plugin for WordPress (versions up to and including 3.0.4) contains a vulnerability to Stored Cross-Site Scripting (XSS). The flaw stems from insufficient input sanitization and output escaping within multi-input sub-fields such as Name, Address, and Checkbox fields. Unlike scalar single-input fields, which are protected by esc_html() in version 3.0.4, these complex sub-fields allow an unauthenticated attacker to inject malicious scripts into the application. Once stored, these scripts execute within the context of a user's browser whenever the affected page is loaded. This poses a significant risk for account takeover or unauthorized actions if an administrative user views the injected content.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to inject malicious web scripts into WordPress pages. If these scripts are executed in the context of an administrator's session, attackers could potentially perform unauthorized administrative actions, steal session cookies, or redirect users to malicious domains.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Repeater Fields for Gravity Forms plugin to the latest version beyond 3.0.4 to ensure proper output escaping is applied to all sub-field types. Monitor server-side web application logs for POST requests containing script tags or JavaScript event handlers directed at endpoints processing Gravity Forms submissions.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>web-vulnerability</category><category>wordpress</category></item></channel></rss>