{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/multi-uploader-for-gravity-forms--1.1.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-5581"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Multi Uploader for Gravity Forms (\u003c= 1.1.8)"],"_cs_severities":["high"],"_cs_tags":["wordpress","cve-2026-5581","arbitrary-file-deletion","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Multi Uploader for Gravity Forms plugin for WordPress (versions 1.1.8 and below) contains a critical vulnerability (CVE-2026-5581) that allows unauthenticated attackers to delete any file from the WordPress media library. The flaw exists within the \u003ccode\u003eplupload_ajax_delete_file()\u003c/code\u003e function, which is improperly registered with the \u003ccode\u003ewp_ajax_nopriv_gfmu_delete_file\u003c/code\u003e hook. Furthermore, the security nonce intended to prevent Cross-Site Request Forgery (CSRF) is inadvertently exposed within the \u003ccode\u003eGFMU_options\u003c/code\u003e JavaScript object on any public-facing page containing a multi-uploader form. Because the function lacks adequate capability checks, an unauthenticated attacker can discover the valid nonce and craft an AJAX request to delete arbitrary attachments by their ID. This vulnerability poses a high risk to WordPress site integrity, as it enables the mass destruction of media assets.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker browses public-facing pages on the target WordPress site to identify presence of the plugin.\u003c/li\u003e\n\u003cli\u003eAttacker inspects page source or JavaScript execution context to extract the \u003ccode\u003eGFMU_options\u003c/code\u003e object.\u003c/li\u003e\n\u003cli\u003eAttacker parses the JavaScript object to obtain the active CSRF nonce value.\u003c/li\u003e\n\u003cli\u003eAttacker identifies target attachment IDs (e.g., via brute force or sequential estimation if ID enumeration is possible).\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the \u003ccode\u003eaction\u003c/code\u003e parameter set to \u003ccode\u003egfmu_delete_file\u003c/code\u003e and provides the valid nonce and target attachment ID.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin function \u003ccode\u003eplupload_ajax_delete_file()\u003c/code\u003e executes the deletion without verifying the user's administrative privileges.\u003c/li\u003e\n\u003cli\u003eThe specified media file is permanently removed from the WordPress media library and storage.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the permanent loss of media library assets. This can disrupt website operations, destroy historical content, and force administrators to rely on backups for restoration. The vulnerability is highly accessible as it does not require prior authentication or elevated permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate this vulnerability:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the \u0026quot;Multi Uploader for Gravity Forms\u0026quot; plugin to the latest version immediately.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to restrict access to the \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e endpoint for actions related to file deletion from unauthenticated sessions.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e involving the \u003ccode\u003egfmu_delete_file\u003c/code\u003e action, especially those lacking associated administrative cookies.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T09:15:43Z","date_published":"2026-08-05T09:15:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-5581/","summary":"The Multi Uploader for Gravity Forms WordPress plugin is vulnerable to unauthenticated arbitrary media deletion via missing capability checks and exposed CSRF nonces.","title":"Unauthenticated Arbitrary Media Deletion in Multi Uploader for Gravity Forms","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-5581/"}],"language":"en","title":"CraftedSignal Threat Feed - Multi Uploader for Gravity Forms (\u003c= 1.1.8)","version":"https://jsonfeed.org/version/1.1"}