Description
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the move_file function used during chunked uploads in the Multi Uploader for Gravity Forms plugin. The function lacks proper validation of the file type, allowing an unauthenticated attacker to upload any file to the server. Uploading a malicious script can lead to remote code execution, giving the attacker full control over the affected WordPress installation.

Affected Systems

Affected vendors and products are sh1zen's Multi Uploader for Gravity Forms plugin for WordPress. All releases through 1.1.9 are vulnerable. No specific patch version is listed in the data, but any installation of the plugin on or before this version is at risk.

Risk and Exploitability

The CVSS score of 9.8 classifies this flaw as critical, while the EPSS score of <1% indicates a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack path is an unauthenticated HTTP request to the plugin's upload endpoint, leveraging chunked file uploads to place an arbitrary file via the vulnerable move_file call. If a malicious script is placed, remote code execution could be achieved.

Generated by OpenCVE AI on September 18, 2026 at 01:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Multi Uploader for Gravity Forms plugin to the latest version that contains the file type validation fix.
  • If an upgrade is not immediately possible, delete or disable the plugin to eliminate the attack surface.
  • Configure the web server or WordPress to restrict uploaded file types and prevent execution of files placed in the uploads directory.
  • Optionally, patch the move_file function manually to enforce strict MIME type and extension checks before saving the file.

Generated by OpenCVE AI on September 18, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Sh1zen
Sh1zen multi Uploader For Gravity Forms
Wordpress
Wordpress wordpress
Vendors & Products Sh1zen
Sh1zen multi Uploader For Gravity Forms
Wordpress
Wordpress wordpress

Thu, 17 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Title Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Sh1zen Multi Uploader For Gravity Forms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T02:13:20.949Z

Reserved: 2026-09-09T09:42:04.055Z

Link: CVE-2026-87796

cve-icon Vulnrichment

Updated: 2026-09-19T02:13:10.230Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T05:17:02.123

Modified: 2026-09-19T03:17:15.720

Link: CVE-2026-87796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:15:16Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type