Executive brief
Gravity Forms is a popular WordPress plugin used to create custom web forms for lead generation and payments. A security flaw allows unauthorized individuals to access and download sensitive files directly from the web server. This could lead to the exposure of configuration files, customer data, or other private information if a form is publicly accessible.
Technical details
A directory traversal vulnerability exists in Gravity Forms up to version 2.10.4 due to insufficient validation of the 'gform_uploaded_files' parameter. An unauthenticated attacker can exploit this by interacting with the 'process_send_resume_link' endpoint on a publicly accessible form. By supplying a crafted path in the vulnerable parameter and a recipient email address, the attacker can trigger the system to send an email notification with the requested server file attached. This allows for the exfiltration of sensitive files such as wp-config.php or other system data.
Affected products
- Gravity Forms Gravity Forms up to, and including, 2.10.4
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory