Threat Advisory

WordPress plugin ‘Gravity Forms’ vulnerable to PHP object injection

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

The widely used WordPress plugin 'Gravity Forms,' which is employed by more than 930,000 websites, has been found to have a vulnerability that allows unauthenticated PHP Object Injection. Gravity Forms is a popular tool utilized by website owners to create various types of forms for interactions and transactions with visitors, such as payments, registrations, and file uploads. Notably, the plugin boasts prominent clients including Airbnb, ESPN, Nike, NASA, PennState, and Unicef.[/subscribe_to_unlock_form]

Summary:

The widely used WordPress plugin 'Gravity Forms,' which is employed by more than 930,000 websites, has been found to have a vulnerability that allows unauthenticated PHP Object Injection. Gravity Forms is a popular tool utilized by website owners to create various types of forms for interactions and transactions with visitors, such as payments, registrations, and file uploads. Notably, the plugin boasts prominent clients including Airbnb, ESPN, Nike, NASA, PennState, and Unicef.[emaillocker id="1283"]

The vulnerability, identified as CVE-2023-28782, affects all versions of the plugin up to 2.73. The issue arises due to a lack of input validation in the 'maybe_unserialize' function, allowing malicious actors to exploit the vulnerability by submitting data through a form created with Gravity Forms. This could lead to arbitrary injection of PHP objects into the application scope, as PHP permits object serialization. The exploitation of CVE-2023-28782 has the potential to result in severe consequences, including arbitrary file access and modification, exfiltration of user/member data, and even remote code execution.

Website owners using the Gravity Forms plugin should be aware of the unauthenticated PHP Object Injection vulnerability and take immediate steps to update the plugin, as well as all other plugins and themes, to the latest versions available. Maintaining a secure and up-to-date WordPress environment is crucial in mitigating the risk of potential exploits and safeguarding sensitive data and functionality on your website.

Recommendations:

  • We strongly recommend you Update the Gravity Forms plugin to version 2.74.

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/wordpress-plugin-gravity-forms-vulnerable-to-php-object-injection/

[/emaillocker]
crossmenu