Arbitrary File Upload Vulnerability in Gravity Forms Plugin by WordPress
CVE-2026-84434

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

What is CVE-2026-84434?

The Gravity Forms plugin for WordPress is susceptible to an Arbitrary File Upload vulnerability in all versions up to and including 3.1.0.4. This weakness arises from a flaw in the file handling process, where validation checks for uploaded files do not properly align with the persistence procedures. As a result, malicious actors can exploit hidden file upload fields in forms that lack adequate validation checks to bypass restrictions and upload potentially harmful executable files. Exposing this vulnerability requires only that the targeted form features a File Upload field set to 'Hidden', enabling unauthenticated attackers to interact with any accessible forms at large.

Affected Version(s)

Gravity Forms 0 <= 3.1.0.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3
.