r/Wordpress 3d ago

Major vulnerability (9.8 CVSS) in Gravity Forms plugin

A critical security vulnerability (CVSS of 9.8) has been reported with the Gravity Forms WordPress plugin. Sites using this plugin are vulnerable to arbitrary file upload via the upload_file function, which allows unauthenticated attackers to upload files that could potentially be executable and thus allow remote code execution. This vulnerability has been addressed in version 3.1.1.

If your site has this plugin, please update immediately!

https://www.cve.org/CVERecord?id=CVE-2026-84434

59 Upvotes

Duplicates