{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/rocketgenius/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rocketgenius:gravity_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-84434"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gravity Forms (\u003c= 3.1.0.4)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","arbitrary-file-upload","rce"],"_cs_type":"advisory","_cs_vendors":["Rocketgenius"],"content_html":"\u003cp\u003eGravity Forms, a popular form-building plugin for WordPress, contains a critical vulnerability (CVE-2026-84434) in versions up to and including 3.1.0.4. The flaw exists within the upload_file() function and stems from a validation bypass when processing File Upload fields configured with 'Hidden' visibility. Because the field validation pipeline and file persistence pipeline operate independently, hidden fields are not subjected to the same extension restrictions as standard fields. Furthermore, rejected files may still be processed by the upload_file() function without secondary validation, enabling unauthenticated remote attackers to upload executable scripts to the web server. Successful exploitation facilitates remote code execution (RCE) on the underlying WordPress environment, representing a severe risk for any site utilizing hidden file upload components on public-facing forms.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running a vulnerable version of Gravity Forms.\u003c/li\u003e\n\u003cli\u003eAttacker probes the site to discover publicly accessible forms containing File Upload fields with 'Hidden' visibility.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request targeting the form submission endpoint, embedding a webshell (e.g., .php extension) within the hidden file field.\u003c/li\u003e\n\u003cli\u003eThe plugin's validation pipeline fails to apply standard extension restrictions due to the field's 'Hidden' status.\u003c/li\u003e\n\u003cli\u003eThe file data is passed to the upload_file() function for persistence.\u003c/li\u003e\n\u003cli\u003eThe web server saves the attacker-supplied file to a reachable directory.\u003c/li\u003e\n\u003cli\u003eAttacker executes the uploaded file via a direct HTTP request to the stored location.\u003c/li\u003e\n\u003cli\u003eAttacker gains RCE and proceeds with further post-exploitation activities.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code on the web server. This leads to full site compromise, potential data exfiltration of user records or database contents, and the installation of persistent backdoors or web shells, affecting any WordPress environment utilizing vulnerable versions of the plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the Gravity Forms plugin to the latest patched version available.\u003c/li\u003e\n\u003cli\u003eAudit all active Gravity Forms on public-facing pages for File Upload fields with 'Hidden' visibility.\u003c/li\u003e\n\u003cli\u003eTemporarily disable File Upload fields in public forms until the plugin is updated.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to form submission endpoints followed by immediate requests to newly created files in the uploads directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T04:08:31Z","date_published":"2026-09-19T04:08:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gravity-forms-rce/","summary":"The Gravity Forms WordPress plugin (\u003c= 3.1.0.4) is susceptible to unauthenticated remote code execution due to a validation flaw in the upload_file function allowing hidden file upload fields to bypass extension checks.","title":"Unauthenticated Arbitrary File Upload in Gravity Forms","url":"https://feed.craftedsignal.io/briefs/2026-09-gravity-forms-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Rocketgenius","version":"https://jsonfeed.org/version/1.1"}