The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
References
Configurations
No configuration.
History
No history.
Information
Published : 2025-12-24 06:15
Updated : 2026-06-17 08:34
NVD link : CVE-2025-13407
Mitre link : CVE-2025-13407
CVE.ORG link : CVE-2025-13407
JSON object : View
Products Affected
No product.
CWE
No CWE.
