CVE Database
/

CVE-2025-13407

Back to search

CVE-2025-13407

Published: Dec 24, 2025

Modified: Dec 24, 2025

PUBLISHED

Description

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

VendorProductVersions

Unknown

Gravity Forms

affected
0 - < 2.9.23.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now