Impact
The vulnerability arises from the move_file function used during chunked uploads in the Multi Uploader for Gravity Forms plugin. The function lacks proper validation of the file type, allowing an unauthenticated attacker to upload any file to the server. Uploading a malicious script can lead to remote code execution, giving the attacker full control over the affected WordPress installation.
Affected Systems
Affected vendors and products are sh1zen's Multi Uploader for Gravity Forms plugin for WordPress. All releases through 1.1.9 are vulnerable. No specific patch version is listed in the data, but any installation of the plugin on or before this version is at risk.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, while the EPSS score of <1% indicates a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack path is an unauthenticated HTTP request to the plugin's upload endpoint, leveraging chunked file uploads to place an arbitrary file via the vulnerable move_file call. If a malicious script is placed, remote code execution could be achieved.
OpenCVE Enrichment