<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Multi Uploader for Gravity Forms (&lt;= 1.1.9) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/multi-uploader-for-gravity-forms--1.1.9/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 05:53:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/multi-uploader-for-gravity-forms--1.1.9/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-87796 - Arbitrary File Upload in Multi Uploader for Gravity Forms</title><link>https://feed.craftedsignal.io/briefs/2026-09-multi-uploader-rce/</link><pubDate>Thu, 17 Sep 2026 05:53:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-multi-uploader-rce/</guid><description>The Multi Uploader for Gravity Forms WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to improper validation in the move_file function, enabling potential remote code execution.</description><content:encoded><![CDATA[<p>The Multi Uploader for Gravity Forms plugin for WordPress (versions up to and including 1.1.9) contains a critical vulnerability (CVE-2026-87796) in its chunked upload handling logic. The vulnerability resides in the move_file function, which fails to adequately validate the type of files being processed during the upload sequence.</p>
<p>This flaw allows an unauthenticated remote attacker to bypass intended file type restrictions and upload arbitrary files, such as malicious PHP scripts, to the web server directory. By successfully uploading a web shell, an attacker can achieve remote code execution, leading to full site compromise. Defenders should prioritize patching or disabling the plugin until an update is applied, as this vulnerability provides a direct pathway for unauthenticated attackers to gain persistent access to the server environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-87796 grants an unauthenticated attacker the ability to execute arbitrary code on the underlying web server. This can lead to total site takeover, data exfiltration, and the deployment of additional malicious payloads. All WordPress sites utilizing the Multi Uploader for Gravity Forms plugin version 1.1.9 or earlier are at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the Multi Uploader for Gravity Forms plugin to the latest version once available to address the move_file function validation logic.</li>
<li>If no patch is available, deactivate the plugin to mitigate the risk of arbitrary file upload.</li>
<li>Monitor web server logs for suspicious POST requests targeting chunked upload endpoints.</li>
<li>Implement file integrity monitoring (FIM) on the WordPress upload directories to detect unauthorized file creations or extensions (e.g., .php, .phtml).</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>