CVE-2025-13407
Unknown
Unknown - Not Provided
Remote Code Execution via File Upload in Gravity Forms Plugin
Publication date: 2025-12-24
Last updated on: 2025-12-24
Assigner: WPScan
Description
Description
The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gravity_forms | gravity_forms | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |