CVE-2026-1396 | magicplugins Magic Conversation for Gravity Forms Plugin up to 3.0.97 on WordPress Shortcode magic-conversation cross site scripting
A vulnerability marked as problematic has been reported in magicplugins Magic Conversation for Gravity Forms Plugin up to 3.0.97 on WordPress. This affects the function magic-conversation of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-1396. Remote exploitation of the attack is possible. No exploit is available.