CRITICAL
9.8 CVE-2026-87796 Published 17 Sept 2026
Multi Uploader for Gravity Forms Plugin Arbitrary File Upload Vulnerability
Worried this affects your website?
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9.
The flaw exists in the move_file function due to insufficient file type validation during chunked upload handling.
- Affected versions: all versions up to and including 1.1.9
- Attackers: unauthenticated
- Impact: arbitrary file upload on the server, which may make remote code execution possible
Reference: CVE-2026-87796 on NVD
← Back to Security News