PT-2025-45404 · WordPress · Gravity Forms

·

CVE-2025-12352

·

Published

2025-11-07

·

Updated

2026-07-13

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gravity Forms versions prior to 2.9.21
Description The Gravity Forms plugin for WordPress contains a flaw that allows unauthenticated attackers to upload arbitrary files to the server. This issue is caused by missing file type validation within the copy post image() function, which could lead to remote code execution. This risk specifically affects sites where the allow url fopen setting is enabled, the post creation form is active, and a file upload field for the post is configured.
Recommendations Update the plugin to a version newer than 2.9.20. As a temporary mitigation, disable the copy post image() function or set allow url fopen to Off in the server configuration.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12352

Affected Products

Gravity Forms