PT-2025-45214 · Pluginscafe+1 · Range Slider Addon For Gravity Forms

CVE-2025-49905

·

Published

2025-10-27

·

Updated

2025-11-06

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Range Slider Addon for Gravity Forms versions prior to 1.1.7
Description Insufficient input sanitization and output escaping lead to Reflected and Stored Cross-Site Scripting (XSS), a condition where arbitrary web scripts are injected into web pages and executed when a user accesses them. This issue allows unauthenticated attackers to execute malicious scripts.
Recommendations Update Range Slider Addon for Gravity Forms to a version newer than 1.1.6.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49905

Affected Products

Range Slider Addon For Gravity Forms