{"id":"CVE-2026-84434","published":"2026-09-19T03:17:15.573","lastModified":"2026-09-21T13:33:33.387","description":"The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. Exploitation requires the targeted form to contain a File Upload field with its Visibility set to 'Hidden'; the vulnerability is reachable by unauthenticated attackers on any publicly accessible form meeting this condition.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-434"],"vendors":[],"products":[],"references":[{"url":"https://docs.gravityforms.com/gravityforms-change-log/","tags":[]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/787e22a9-329b-4e71-bc2a-4f5524fc9356?source=cve","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This flaw allows unauthenticated attackers to upload executable files via a hidden File Upload field in Gravity Forms for WordPress, leading to potential remote code execution.","exploitability":"Exploitation requires the targeted form to contain a File Upload field with its Visibility set to 'Hidden'. This makes it moderately exploitable by unauthenticated attackers on any publicly accessible form meeting this condition.","blast_radius":"If exploited, the vulnerability could result in remote code execution on the affected WordPress site, potentially leading to full compromise of the site and loss of sensitive data.","remediation":"Disable the File Upload feature for any form fields with Visibility set to 'Hidden' or upgrade to Gravity Forms version 3.1.0.5 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","upload","wp","form"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T09:00:25.314Z"}}