Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 24 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 24 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Title | GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-12-24T16:39:08.316Z
Reserved: 2025-11-19T14:15:25.528Z
Link: CVE-2025-13407
Updated: 2025-12-24T16:39:04.028Z
Status : Received
Published: 2025-12-24T06:15:43.973
Modified: 2025-12-24T17:15:46.577
Link: CVE-2025-13407
No data.
OpenCVE Enrichment
No data.
No weakness.