Junglewise Threat Intelligence

CVE-2026-12997: Gravity Forms Directory Traversal in gform_uploaded_files parameter

CVE-2026-12997 · Severity: high · CVSS 7.5 · Published 2026-07-15

Technologies: Rocketgenius Gravity Forms. Vendors: Rocketgenius, Gravity Forms.

Executive brief

Gravity Forms is a popular WordPress plugin used to create custom web forms for lead generation and payments. A security flaw allows unauthorized individuals to access and download sensitive files directly from the web server. This could lead to the exposure of configuration files, customer data, or other private information if a form is publicly accessible.

Technical details

A directory traversal vulnerability exists in Gravity Forms up to version 2.10.4 due to insufficient validation of the 'gform_uploaded_files' parameter. An unauthenticated attacker can exploit this by interacting with the 'process_send_resume_link' endpoint on a publicly accessible form. By supplying a crafted path in the vulnerable parameter and a recipient email address, the attacker can trigger the system to send an email notification with the requested server file attached. This allows for the exfiltration of sensitive files such as wp-config.php or other system data.

Affected products

  • Gravity Forms Gravity Forms up to, and including, 2.10.4

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory

References

Related threats