Arbitrary File Upload Vulnerability in Gravity Forms Plugin by WordPress
CVE-2026-84434
9.8CRITICAL
What is CVE-2026-84434?
The Gravity Forms plugin for WordPress is susceptible to an Arbitrary File Upload vulnerability in all versions up to and including 3.1.0.4. This weakness arises from a flaw in the file handling process, where validation checks for uploaded files do not properly align with the persistence procedures. As a result, malicious actors can exploit hidden file upload fields in forms that lack adequate validation checks to bypass restrictions and upload potentially harmful executable files. Exposing this vulnerability requires only that the targeted form features a File Upload field set to 'Hidden', enabling unauthenticated attackers to interact with any accessible forms at large.
Affected Version(s)
Gravity Forms 0 <= 3.1.0.4