PT-2025-47239 · WordPress · Gravity Forms

Talal Nasraddeen

·

Published

2025-11-18

·

Updated

2025-11-23

·

CVE-2025-12974

CVSS v3.1
8.1
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gravity Forms versions prior to 2.9.22
Description The Gravity Forms plugin for WordPress is susceptible to arbitrary file uploads because of inadequate file type validation within the legacy chunked upload mechanism. The extension blacklist does not include .phar files, allowing unauthenticated attackers to upload executable .phar files. Successful exploitation requires the web server to be configured to process .phar files as PHP. This could lead to remote code execution on the server if an attacker can determine the upload path.
Recommendations Update Gravity Forms to version 2.9.22 or later.

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12974

Affected Products

Gravity Forms