CVE-2023-28782

WordPress Gravity Forms Plugin <= 2.7.3 is vulnerable to PHP Object Injection

Deserialization of Untrusted Data vulnerability in Rocketgenius Inc. Gravity Forms.This issue affects Gravity Forms: from n/a through 2.7.3.


We have discovered 65,632 live websites that are affected by CVE-2023-28782.

Run a Free Instant Scan




Affected Software

Product  Gravity Forms
Category Wordpress Plugins
Vulnerable Domains65,632 live websites (14% of Gravity Forms install base)
Vulnerable Versions
  • from 0 through 2.7.3
Vulnerable Versions Count330 versions ( 70% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Dec 20, 2023
  • Updated - Apr 28, 2026

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2023-28782
United States36,315 websites



GB3,626 websites
Australia3,366 websites
Canada3,293 websites
France2,640 websites
Netherlands2,300 websites
Germany2,105 websites
Italy1,204 websites
Spain927 websites
Denmark876 websites

Website Distribution by TLD

Number of websites using CVE-2023-28782
.com37,394 websites
.org3,368 websites
.com.au3,197 websites
.co.uk2,533 websites
.nl2,076 websites
.ca2,029 websites
.fr1,745 websites
.net1,574 websites
.de971 websites
.it884 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-28782

Top websites that are affected by CVE-2023-28782. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com United States*,***
************.ie United States*,***
******.com United States*,***
***************.org United States*,***
*****.**.uk United States**,***
********.com United States**,***
****.com United States**,***
****.com United States**,***
*********.net Germany**,***
***********.com United States**,***
See full domain list

FAQ

CVE-2023-28782 is Deserialization of Untrusted Data in Gravity Forms
A total of 65,632 websites have been identified as vulnerable to CVE-2023-28782, based on global website indexing conducted by WebTechSurvey.
The Gravity Forms is affected by the CVE-2023-28782 vulnerability.
Gravity Forms versions up to and including 2.7.3 are vulnerable to CVE-2023-28782.