Arbitrary File Upload Vulnerability in Multi Uploader for Gravity Forms Plugin by WordPress
CVE-2026-87796
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-87796?
The Multi Uploader for Gravity Forms plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to a failure in proper file type validation during the chunked upload process. This weakness allows unauthorized attackers to upload any file to the server hosting the website, potentially facilitating remote code execution and compromising the site's security. It is crucial for users of this plugin to immediately assess their systems and implement necessary updates or mitigations to safeguard against potential exploits.
Affected Version(s)
Multi Uploader for Gravity Forms 0 <= 1.1.9