ZeroHour
Wordfencepublished ()ingested Alex Thomas

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

highVulnerabilityimportance 58
AI summary · glm-5.3-flash

Wordfence finds an unauthenticated arbitrary file upload flaw in Gravity Forms (1M+ installs) that can lead to remote code execution.

On August 9, 2026, Wordfence's Argus scanner discovered an unauthenticated arbitrary file upload vulnerability in the WordPress plugin Gravity Forms, estimated at over one million active installations. Attackers can write files with attacker-selected extensions to a public temporary upload directory, potentially enabling remote code execution. The post does not mention a CVE identifier or observed exploitation.

  • Gravity Forms has more than one million active WordPress installations
  • Unauthenticated attackers can write files with arbitrary extensions to a public temp upload directory
  • File upload can be leveraged toward remote code execution
  • Flaw discovered by Wordfence Argus automated threat-intelligence tooling on August 9, 2026
Full article

On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upload directory. This can lead to remote code execution. The post Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms appeared first on Wordfence.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.