CYBERHAWK / CVE / CVE-2026-5109

CVE-2026-5109

Gravity Forms WordPress Plugin

HIGH CVSS 7.2 vibe

The flaw

Stored XSS vulnerability in Product Option field values bypasses sanitization.

What to do

Update to version 2.10.1 or later

▸ Scan my repo for CVE-2026-5109

References

First seen 2026-05-08 · Tracked by PickBits CyberHawk · Weekly CVE digest