CVE-2026-74004: WordPress Gravity Booster – Styles & Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control vulnerability
Published Aug 18, 2026
·Updated
Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.
Affected Software
1 affected component
WordPress Gravity Booster - Styles & Layouts for Gravity Forms<=6.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Sites running version 6.0 or earlier are identified as affected. The issue is in the WordPress Gravity Booster - Styles & Layouts for Gravity Forms plugin.
2
What level of access does an attacker need?
An attacker needs subscriber-level access to the WordPress site. The CVSS vector indicates the issue can be exploited over the network with low attack complexity and without user interaction.
3
What is the likely impact?
Successful exploitation can result in low-impact confidentiality and integrity effects. No availability impact is indicated.