CVE-2026-94120: WordPress GravityExport Lite for Gravity Forms plugin <= 2.7.2 - Broken Access Control vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
Affected Software
1 affected component
Gravity Forms GravityExport Lite for Gravity Forms<=2.7.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GravityExport Lite for Gravity Formsto a version that resolves this vulnerability.Fixed in 2.7.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The CVSS vector indicates it is remotely exploitable over the network with low attack complexity and no user interaction.
2
What is the likely impact of successful exploitation?
The reported impact is high confidentiality impact, meaning an attacker may be able to access sensitive information. No integrity or availability impact is reported.
3
Which plugin versions are known to be affected?
GravityExport Lite for Gravity Forms versions 2.7.2 and earlier are identified as affected.