CVE-2025-68863
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Reflected XSS in iContact for Gravity Forms plugin (≤1.3.2) allows attackers to inject malicious scripts via crafted requests, requiring user interaction.
The iContact for Gravity Forms WordPress plugin, versions 1.3.2 and earlier, contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw allows an attacker to inject arbitrary HTML and JavaScript into a response, which is then executed in the victim's browser.
Exploitation requires a privileged user, such as an administrator, to perform an action like clicking a malicious link or visiting a crafted page [1]. The attacker does not need authentication but must trick the target into interacting with the crafted request. This makes the vulnerability suitable for mass-exploit campaigns targeting thousands of sites regardless of size or popularity [1].
Successful exploitation enables the attacker to inject malicious scripts, including redirects, advertisements, and other HTML payloads, which execute when visitors access the affected site [1]. This could lead to site defacement, credential theft, or further compromise of the WordPress installation.
As of the advisory, no official patch has been released, but Patchstack has issued a mitigation rule to block attacks until an update can be applied [1]. Users are strongly advised to update the plugin to the latest available version or implement a virtual patch to protect their sites.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=1.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.