{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gravity-forms--3.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gravity_forms:gravity_forms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-19513"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gravity Forms (\u003c= 3.0.2)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","rce","xss"],"_cs_type":"advisory","_cs_vendors":["Gravity Forms"],"content_html":"\u003cp\u003eGravity Forms versions up to and including 3.0.2 contain a critical vulnerability in the \u003ccode\u003eGFAsyncUpload::upload()\u003c/code\u003e function. The flaw stems from insufficient validation of multi-file upload chunk state, allowing the reuse of public form state URL hashes as chunk continuation hashes. Attackers can leverage this to influence the temporary filename used during the upload process.\u003c/p\u003e\n\u003cp\u003eWhen a public-facing form includes a File Upload field with the \u0026quot;Multiple Files\u0026quot; option enabled, an unauthenticated attacker can upload files to the plugin's temporary storage directory. On web servers that do not honor \u003ccode\u003e.htaccess\u003c/code\u003e files (e.g., NGINX), this allows for the upload of executable PHP code, resulting in remote code execution. In environments where the plugin successfully places a \u003ccode\u003e.htaccess\u003c/code\u003e file to block PHP execution, the vulnerability still allows for stored cross-site scripting (XSS) if an attacker uploads malicious HTML files that are subsequently accessed by users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running a vulnerable version of Gravity Forms (\u0026lt;= 3.0.2).\u003c/li\u003e\n\u003cli\u003eAttacker discovers a public form containing a File Upload field with \u0026quot;Multiple Files\u0026quot; enabled.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious payload (e.g., PHP polyglot or malicious HTML).\u003c/li\u003e\n\u003cli\u003eAttacker performs a multipart file upload request to the \u003ccode\u003eGFAsyncUpload::upload()\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker manipulates the chunk continuation hash to control the destination filename in the temporary upload directory.\u003c/li\u003e\n\u003cli\u003eServer processes the request and writes the malicious file to the storage directory.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the file URL to trigger execution (RCE) or XSS.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation can lead to full remote code execution on the underlying server if it does not properly restrict execution in the temporary directory. In secondary scenarios, attackers can achieve stored XSS, allowing for session hijacking or further compromise of authenticated administrative users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for the detection engineering and security operations teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Gravity Forms plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eImplement a web application firewall (WAF) rule to block POST requests to Gravity Forms upload endpoints that contain suspicious filename extensions (e.g., .php, .html, .js) if upgrading is delayed.\u003c/li\u003e\n\u003cli\u003eAudit the temporary upload directory for unauthorized files, particularly those with executable extensions.\u003c/li\u003e\n\u003cli\u003eEnsure the web server configuration explicitly denies execution of files in the Gravity Forms temporary upload directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T15:07:06Z","date_published":"2026-09-01T15:07:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gravity-forms-arbitrary-upload/","summary":"An arbitrary file upload vulnerability in the Gravity Forms WordPress plugin (\u003c= 3.0.2) allows unauthenticated attackers to write arbitrary files to the temporary upload directory, potentially leading to remote code execution or stored XSS.","title":"Arbitrary File Upload Vulnerability in Gravity Forms","url":"https://feed.craftedsignal.io/briefs/2026-09-gravity-forms-arbitrary-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - Gravity Forms (\u003c= 3.0.2)","version":"https://jsonfeed.org/version/1.1"}