CVE-2026-4394 | Gravity Forms Plugin up to 2.9.30 on WordPress Dashboard get_value_entry_detail input_.4 cross site scripting (CNNVD-202604-1900)
A vulnerability, which was classified as problematic, has been found in Gravity Forms Plugin up to 2.9.30 on WordPress. Affected by this vulnerability is the function get_value_entry_detail of the component Dashboard. This manipulation of the argument input_.4 causes cross site scripting.
This vulnerability appears as CVE-2026-4394. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.