Arbitrary Media Deletion in Gravity Forms Multi Uploader Plugin for WordPress
CVE-2026-5581

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 August 2026

What is CVE-2026-5581?

The Multi Uploader for Gravity Forms plugin in WordPress exhibits a vulnerability that allows unauthorized users to delete media files arbitrarily. This flaw arises from insufficient capability checks within the plupload_ajax_delete_file function, allowing unauthenticated attackers to exploit the exposed nonce for CSRF protection. By supplying a valid attachment ID, attackers can permanently remove any media file from the WordPress media library, potentially leading to the complete loss of media assets. Proper security measures and updates are essential to mitigate the risk posed by this vulnerability.

Affected Version(s)

Multi Uploader for Gravity Forms 0 <= 1.1.8

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Riski Gana Prasetya
.