CRITICAL 9.8 CVE-2026-84434 Published 19 Sept 2026

Gravity Forms WordPress Plugin Arbitrary File Upload Vulnerability

Worried this affects your website?

The Gravity Forms plugin for WordPress is vulnerable to an Arbitrary File Upload flaw in all versions up to and including 3.1.0.4, via the upload_file function.

The issue stems from a mismatch between the field validation pipeline and the file persistence pipeline. Hidden file upload fields bypass extension validation, and a rejected file's intact upload state is later passed to upload_file() without re-validation.

  • Affected versions: all versions up to and including 3.1.0.4
  • Precondition: the targeted form must contain a File Upload field with Visibility set to 'Hidden'
  • Impact: unauthenticated attackers can upload potentially executable files, leading to remote code execution

Reference: CVE-2026-84434 on NVD

← Back to Security News