PT-2025-45404 · WordPress · Gravity Forms
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gravity Forms versions prior to 2.9.21
Description
The Gravity Forms plugin for WordPress contains a flaw that allows unauthenticated attackers to upload arbitrary files to the server. This issue is caused by missing file type validation within the
copy post image() function, which could lead to remote code execution. This risk specifically affects sites where the allow url fopen setting is enabled, the post creation form is active, and a file upload field for the post is configured.Recommendations
Update the plugin to a version newer than 2.9.20.
As a temporary mitigation, disable the
copy post image() function or set allow url fopen to Off in the server configuration.Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gravity Forms