Executive brief
The Multi Uploader for Gravity Forms is a WordPress plugin that handles file uploads. An unauthenticated attacker can bypass file type validation during chunked uploads to place arbitrary files on the server, potentially leading to remote code execution and complete website compromise.
Technical details
The plugin contains an arbitrary file upload vulnerability in the move_file function due to insufficient file type validation during chunked upload processing. The vulnerability is unauthenticated and remotely exploitable via a network attack vector. An attacker can craft a malicious chunked upload request to bypass file restrictions and upload executable files (such as PHP) to the web server, achieving remote code execution. The vulnerability affects all versions up to and including 1.1.9.
Affected products
- WP Mulesoft Multi Uploader for Gravity Forms up to and including 1.1.9
Timeline
- 2026-09-17: disclosed