Arbitrary File Upload Vulnerability in Gravity Forms Plugin for WordPress
CVE-2026-19513

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 September 2026

What is CVE-2026-19513?

The Gravity Forms plugin for WordPress suffers from an Arbitrary File Upload vulnerability due to inadequate validation in managing multi-file uploads. The flaw arises from the GFAsyncUpload::upload() function, which improperly handles public form state URL hashes and allows unauthenticated attackers to upload files with malicious intent. This vulnerability enables attackers to upload specially crafted files, such as a PNG/PDF polyglot, to a user-defined filename in the plugin's temporary upload directory. Although a .htaccess file is generated on plugin installation which helps mitigate some aspects of exploitation, systems using servers like NGINX—where .htaccess rules are not applicable—remain at risk for remote code execution. In scenarios where PHP execution is blocked, the vulnerability could still facilitate stored cross-site scripting attacks, presenting further security concerns.

Affected Version(s)

Gravity Forms 0 <= 3.0.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Thomas
Wordfence Argus
.