PT-2025-47239 · WordPress · Gravity Forms
Talal Nasraddeen
·
Published
2025-11-18
·
Updated
2026-04-14
·
CVE-2025-12974
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gravity Forms versions prior to 2.9.22
Description
The Gravity Forms plugin for WordPress is susceptible to arbitrary file uploads because of inadequate file type validation within the legacy chunked upload mechanism. The extension blacklist does not include .phar files, allowing unauthenticated attackers to upload executable .phar files. Successful exploitation requires the web server to be configured to process .phar files as PHP. This could lead to remote code execution on the server if an attacker can determine the upload path.
Recommendations
Update Gravity Forms to version 2.9.22 or later.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gravity Forms