High severity7.5NVD Advisory· Published Jun 2, 2020· Updated Jun 17, 2026
CVE-2020-13764
CVE-2020-13764
Description
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wp-premium/gravityformsPackagist | < 2.4.9 | 2.4.9 |
Affected products
3- WordPress/Gravity Forms plugindescription
Patches
Vulnerability mechanics
References
5- docs.gravityforms.com/gravityforms-change-log/nvdVendor Advisory
- github.com/advisories/GHSA-m983-q76g-cwpqghsaADVISORY
- github.com/wp-premium/gravityforms/compare/2.4.8...2.4.9nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-13764ghsaADVISORY
- docs.gravityforms.com/gravityforms-change-logghsaWEB
News mentions
0No linked articles in our index yet.