Gravity Forms is vulnerable to Unrestricted File Upload
98
Critical Risk
upload_file() persists a submitted file after the field validation pipeline has already run. Hidden File Upload fields skip extension checks, and a rejected upload's intact file state is later passed to upload_file() without being validated again. An unauthenticated visitor to a public form can therefore store an executable file and achieve remote code execution. The fix re-validates hidden File Upload fields before the file is persisted.
You are affected if you are using a version that falls within the vulnerable range and a publicly accessible form contains a File Upload field with Visibility set to Hidden.
Gravity Forms is vulnerable to Unrestricted File Upload in versions 0.0.1 - 3.1.0.4.
Upgrade the gravityforms and/or the Gravity Forms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.