Arbitrary Media Deletion in Gravity Forms Multi Uploader Plugin for WordPress
CVE-2026-5581
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-5581?
The Multi Uploader for Gravity Forms plugin in WordPress exhibits a vulnerability that allows unauthorized users to delete media files arbitrarily. This flaw arises from insufficient capability checks within the plupload_ajax_delete_file function, allowing unauthenticated attackers to exploit the exposed nonce for CSRF protection. By supplying a valid attachment ID, attackers can permanently remove any media file from the WordPress media library, potentially leading to the complete loss of media assets. Proper security measures and updates are essential to mitigate the risk posed by this vulnerability.
Affected Version(s)
Multi Uploader for Gravity Forms 0 <= 1.1.8