The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Title | GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-12-24T06:00:04.578Z
Reserved: 2025-11-19T14:15:25.528Z
Link: CVE-2025-13407
No data.
Status : Received
Published: 2025-12-24T06:15:43.973
Modified: 2025-12-24T06:15:43.973
Link: CVE-2025-13407
No data.
OpenCVE Enrichment
No data.