← Back to search

CVE-2026-84434

9.8 CRITICAL

Published 2026-09-19 · Updated 2026-09-21

AI risk analysis

Summary
This flaw allows unauthenticated attackers to upload executable files via a hidden File Upload field in Gravity Forms for WordPress, leading to potential remote code execution.
Exploitability
Exploitation requires the targeted form to contain a File Upload field with its Visibility set to 'Hidden'. This makes it moderately exploitable by unauthenticated attackers on any publicly accessible form meeting this condition.
Blast radius
If exploited, the vulnerability could result in remote code execution on the affected WordPress site, potentially leading to full compromise of the site and loss of sensitive data.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the File Upload feature for any form fields with Visibility set to 'Hidden' or upgrade to Gravity Forms version 3.1.0.5 or later.
rcewebuploadwpform

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipeline, where hidden file upload fields bypass extension validation and a rejected file's intact upload state is later passed to upload_file() without re-validation. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. Exploitation requires the targeted form to contain a File Upload field with its Visibility set to 'Hidden'; the vulnerability is reachable by unauthenticated attackers on any publicly accessible form meeting this condition.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.