External risk intelligence

WordPress Gravity Forms Multi Uploader Arbitrary File Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-14344

This vulnerability affects a WordPress plugin, which is designed to be public-facing and accessible via the internet as a standard web application component. Since the vulnerable function is reachable by unauthenticated users, the attack surface is exposed directly to the public internet.

Path Traversal

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in a WordPress plugin allows attackers to delete any file on the server without needing any special access. This could potentially impact the integrity and availability of your website's data and operations. The main concern is to determine if your organization utilizes this specific plugin and, if so, to assess the potential exposure.

  • Attackers can delete any files on the server.
  • Affects publicly accessible WordPress websites.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a request to the vulnerable WordPress plugin. This could allow them to delete arbitrary files from the server, potentially leading to a denial-of-service condition or unauthorized data exposure.

  • No authentication required to attack.
  • Target the file deletion function.
  • Arbitrary file deletion risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to delete any file on the server if the affected plugin is installed. This is because the plugin does not properly validate file paths when handling file deletion requests.

  • Arbitrary files on the server.
  • Unauthenticated access to delete files.
  • Server instability or data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WordPress plugin's arbitrary file deletion vulnerability likely impacts website owners and their web hosting or platform administration teams. The immediate first step is to identify all instances of the "Multi Uploader for Gravity Forms" plugin across your WordPress deployments, confirm which are exposed to the internet and host business-critical data, and then assign ownership for remediation planning.

  • Website owners should own the issue.
  • Verify plugin reachability and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Multi Uploader for Gravity Forms plugin?

This is a WordPress plugin designed to enhance the Gravity Forms experience by allowing users to upload multiple files simultaneously. It functions as an extension to the popular forms builder, providing specific back-end logic to handle file management and processing tasks when users submit data through a website form.

How does CWE-22 relate to CVE-2025-14344?

CVE-2025-14344 is an instance of CWE-22, which is Improper Limitation of a Pathname to a Restricted Directory. In plain terms, the plugin fails to check if a requested file path is authorized, allowing an attacker to navigate outside intended folders and target sensitive system files for deletion.

Do I need to be logged into WordPress to trigger this?

No, authentication is not required. An attacker can trigger this vulnerability by sending a specifically crafted network request directly to the vulnerable function. Merely visiting the site as a regular user or simply browsing it does not trigger the deletion; the attacker must intentionally send a malicious request designed to target the file deletion logic.

Is my WordPress site at risk according to Halo Surface Signal?

Yes, if you use this plugin. Halo Surface Signal identifies this as an external risk because the plugin is designed to be public-facing as part of a standard WordPress web application. Because the affected function is reachable over the internet by anyone, your site's file system is potentially exposed to unauthenticated remote deletion attempts.

When should I take action to secure my server?

You should act immediately. Start by auditing your WordPress installations to locate any instances of this specific plugin. Once identified, evaluate the criticality of the hosted data and prioritize these environments for remediation to prevent potential service disruption or unauthorized file loss.

References