{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/multi-uploader-for-gravity-forms--1.1.9/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:multi_uploader_for_gravity_forms_project:multi_uploader_for_gravity_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-87796"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=50DBF5BF-01EC-5C75-8FD8-ADF17DA2C4CE\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Multi Uploader for Gravity Forms (\u003c= 1.1.9)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Multi Uploader for Gravity Forms plugin for WordPress (versions up to and including 1.1.9) contains a critical vulnerability (CVE-2026-87796) in its chunked upload handling logic. The vulnerability resides in the move_file function, which fails to adequately validate the type of files being processed during the upload sequence.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an unauthenticated remote attacker to bypass intended file type restrictions and upload arbitrary files, such as malicious PHP scripts, to the web server directory. By successfully uploading a web shell, an attacker can achieve remote code execution, leading to full site compromise. Defenders should prioritize patching or disabling the plugin until an update is applied, as this vulnerability provides a direct pathway for unauthenticated attackers to gain persistent access to the server environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-87796 grants an unauthenticated attacker the ability to execute arbitrary code on the underlying web server. This can lead to total site takeover, data exfiltration, and the deployment of additional malicious payloads. All WordPress sites utilizing the Multi Uploader for Gravity Forms plugin version 1.1.9 or earlier are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Multi Uploader for Gravity Forms plugin to the latest version once available to address the move_file function validation logic.\u003c/li\u003e\n\u003cli\u003eIf no patch is available, deactivate the plugin to mitigate the risk of arbitrary file upload.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests targeting chunked upload endpoints.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) on the WordPress upload directories to detect unauthorized file creations or extensions (e.g., .php, .phtml).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T01:22:39Z","date_published":"2026-09-17T05:53:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-multi-uploader-rce/","summary":"The Multi Uploader for Gravity Forms WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to improper validation in the move_file function, enabling potential remote code execution.","title":"CVE-2026-87796 - Arbitrary File Upload in Multi Uploader for Gravity Forms","url":"https://feed.craftedsignal.io/briefs/2026-09-multi-uploader-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Multi Uploader for Gravity Forms (\u003c= 1.1.9)","version":"https://jsonfeed.org/version/1.1"}