Gravity Forms: Multiple Form Instances
Gravity Forms: Multiple Form Instances has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for Gravity Forms: Multiple Form Instances has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. Gravity Forms: Multiple Form Instances is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.5.33.
CVE-2024-6550Gravity Forms: Multiple Form Instances <= 1.1.1 - Unauthenticated Full Path Disclosure
Read the full analysisVulnerability Records

Gravity Forms: Multiple Form Instances
Author
Marin Atanasov
Gravity Forms: Multiple Form Instances is used in conjunction with the awesome Gravity Forms plugin. Usually, when you use multiple Gravity Forms with AJAX enabled on the same page, this causes issues with multiple form submission & error display, infinite loading and other issues. This plugin addresses this issue, allowing multiple forms to be displayed on the same page without any issues.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C