Impact
The vulnerability in Gravity Forms allows an attacker to upload arbitrary files through a hidden form field that bypasses the extension validation pipeline. Because the upload state of a rejected file is later re‑used without re‑validation, an attacker can place executable code in the file. This flaw can lead to remote code execution on the hosting server. The weakness is an example of improper file validation (CWE-434).
Affected Systems
All installations of the Gravity Forms plugin for WordPress with a version of 3.1.0.4 or earlier are affected. The issue exists in every form that contains a File Upload field whose visibility is set to Hidden.
Risk and Exploitability
The flaw carries a CVSS score of 9.8, indicating critical severity. The EPSS score is 3%, indicating moderate exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers need only access a publicly available form that includes a hidden file upload field; no authentication is required. Its execution path is through an HTTP request to the Gravity Forms upload handler, making it exploitable from any internet‑connected location.
OpenCVE Enrichment