Arbitrary File Upload Vulnerability in Gravity Forms Plugin for WordPress
CVE-2026-19513
What is CVE-2026-19513?
The Gravity Forms plugin for WordPress suffers from an Arbitrary File Upload vulnerability due to inadequate validation in managing multi-file uploads. The flaw arises from the GFAsyncUpload::upload() function, which improperly handles public form state URL hashes and allows unauthenticated attackers to upload files with malicious intent. This vulnerability enables attackers to upload specially crafted files, such as a PNG/PDF polyglot, to a user-defined filename in the plugin's temporary upload directory. Although a .htaccess file is generated on plugin installation which helps mitigate some aspects of exploitation, systems using servers like NGINX—where .htaccess rules are not applicable—remain at risk for remote code execution. In scenarios where PHP execution is blocked, the vulnerability could still facilitate stored cross-site scripting attacks, presenting further security concerns.
Affected Version(s)
Gravity Forms 0 <= 3.0.2