No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gravityforms
Gravityforms gravity Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Gravityforms
Gravityforms gravity Forms Wordpress Wordpress wordpress |
Wed, 24 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 24 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path. | |
| Title | GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-12-24T16:39:08.316Z
Reserved: 2025-11-19T14:15:25.528Z
Link: CVE-2025-13407
Updated: 2025-12-24T16:39:04.028Z
Status : Deferred
Published: 2025-12-24T06:15:43.973
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13407
No data.
OpenCVE Enrichment
Updated: 2025-12-29T22:34:40Z
No weakness.