VYPR
High severity7.1NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2025-68863

CVE-2025-68863

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zack Katz iContact for Gravity Forms gravity-forms-icontact allows Reflected XSS.This issue affects iContact for Gravity Forms: from n/a through <= 1.3.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in iContact for Gravity Forms plugin (≤1.3.2) allows attackers to inject malicious scripts via crafted requests, requiring user interaction.

The iContact for Gravity Forms WordPress plugin, versions 1.3.2 and earlier, contains a reflected cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation [1]. This flaw allows an attacker to inject arbitrary HTML and JavaScript into a response, which is then executed in the victim's browser.

Exploitation requires a privileged user, such as an administrator, to perform an action like clicking a malicious link or visiting a crafted page [1]. The attacker does not need authentication but must trick the target into interacting with the crafted request. This makes the vulnerability suitable for mass-exploit campaigns targeting thousands of sites regardless of size or popularity [1].

Successful exploitation enables the attacker to inject malicious scripts, including redirects, advertisements, and other HTML payloads, which execute when visitors access the affected site [1]. This could lead to site defacement, credential theft, or further compromise of the WordPress installation.

As of the advisory, no official patch has been released, but Patchstack has issued a mitigation rule to block attacks until an update can be applied [1]. Users are strongly advised to update the plugin to the latest available version or implement a virtual patch to protect their sites.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.