Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability in the Multi Uploader for Gravity Forms WordPress plugin allows unauthenticated attackers to delete any media attachment. This could lead to the destruction of the entire media library.
- Unauthorized media deletion affects WordPress.
- Confirms relevance and exposure to WordPress media loss.
- Verify if WordPress media deletion is a concern.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by leveraging a publicly exposed nonce found on any page with a multi-uploader form. By identifying the attachment ID of a media file, the attacker can trigger the vulnerable function to delete that file, potentially leading to the destruction of the entire media library.
- Accessible via public-facing forms.
- Triggers deletion of media attachments.
- Risk of complete media library destruction.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to delete any media file from a WordPress site when the Multi Uploader for Gravity Forms plugin is present and a multi-uploader form is displayed. This could lead to the permanent removal of all media attachments within the WordPress media library.
- Media attachments
- Via exposed JavaScript object
- Complete media library destruction
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in a WordPress plugin affects any site utilizing the Multi Uploader for Gravity Forms. The primary teams to engage would be the application owners responsible for the WordPress instances and the platform or infrastructure teams managing the web servers. The immediate first step is to identify all WordPress sites using this plugin, confirm their exposure and criticality, and then assign ownership for remediation planning.
- WordPress application owners must triage.
- Verify plugin usage and exposure.
- Plan remediation or mitigation.