The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gravityforms
Gravityforms gravity Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Gravityforms
Gravityforms gravity Forms Wordpress Wordpress wordpress |
Wed, 24 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 24 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Title | GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-12-24T06:00:04.578Z
Updated: 2025-12-24T16:39:08.316Z
Reserved: 2025-11-19T14:15:25.528Z
Link: CVE-2025-13407
Updated: 2025-12-24T16:39:04.028Z
Status : Awaiting Analysis
Published: 2025-12-24T06:15:43.973
Modified: 2025-12-29T15:58:56.260
Link: CVE-2025-13407
No data.