OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-94120

HIGH · CVSS 7.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

GravityExport Lite for Gravity Forms versions up to 2.7.2 is susceptible to unauthenticated broken access control, allowing attackers to exploit this vulnerability to gain unauthorized access to sensitive data or functionality. Organizations using this plugin should prioritize patching or mitigating this vulnerability to protect their systems from potential data breaches and unauthorized actions. Immediate action is recommended for those managing web applications that utilize this plugin.

CVE
CVE-2026-94120
Severity
HIGH
CVSS
7.5
EPSS
0.29%

Original NVD Description

Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.