External risk intelligence

Gravity Forms WordPress Plugin Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-84434

The vulnerability affects a WordPress plugin used for forms, which are commonly deployed as public-facing web elements. Because the vulnerability is reachable on any publicly accessible form that meets the specific configuration criteria, it is frequently exposed to the internet in typical website deployments.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the Gravity Forms plugin for WordPress, impacting its file upload functionality. This issue allows unauthenticated attackers to potentially upload and execute malicious files on affected systems, which could lead to remote code execution. The primary concern is confirming if any publicly accessible forms are configured in a way that exposes this vulnerability.

  • Uploads can bypass security checks.
  • Public forms with hidden uploads are at risk.
  • Confirm exposure to assess potential impact.

Attack Path

How an attacker could exploit the issue

An attacker can target any publicly accessible WordPress website using the Gravity Forms plugin if the form includes a hidden file upload field. The attacker exploits a flaw in how the plugin handles file uploads, bypassing security checks for files that were previously rejected. This allows them to upload malicious files, potentially leading to remote code execution on the server.

  • Entry condition: Publicly accessible form with hidden file upload field.
  • Trigger point: Uploading a file that bypasses extension validation.
  • Resulting risk: Remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthenticated attackers could upload executable files to a WordPress site via a form. This could lead to remote code execution if the targeted form has a hidden file upload field and the plugin is configured to accept such uploads.

  • Executable files could be uploaded.
  • Hidden file upload fields could bypass validation.
  • Remote code execution on the server.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Gravity Forms plugin's arbitrary file upload vulnerability impacts WordPress sites, making application owners and platform teams responsible for remediation. The immediate priority is to identify all instances of the affected plugin, confirm if any forms have hidden file upload fields, and assess their public accessibility and business criticality to prioritize patching or applying workarounds.

  • Application owners should address the vulnerability.
  • Verify forms with hidden file upload fields.
  • Plan remediation based on exposure and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Gravity Forms plugin?

Gravity Forms is a popular WordPress plugin designed for creating interactive forms that collect user data, handle file submissions, and manage workflows directly within a website's dashboard.

What does CWE-434 mean for CVE-2026-84434?

CWE-434 identifies this as an Unrestricted Upload of File with Dangerous Type. In this specific case, the plugin fails to properly validate files, allowing unauthorized users to store potentially executable code on the server.

How does an attacker trigger this vulnerability?

An attacker initiates the vulnerability by interacting with a public-facing form containing a 'Hidden' visibility file upload field. If a file upload is attempted, the plugin's logic fails to re-validate the request, permitting the storage of malicious files. Forms without hidden file upload fields remain unaffected by this specific flaw.

Is my WordPress site at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because this plugin is frequently used for public-facing web elements, sites utilizing Gravity Forms are likely exposed to the internet. If you host forms accessible to the general public, your environment has a higher probability of being reachable by an attacker.

What should I do to secure my WordPress site?

Prioritize identifying all forms configured with hidden file upload fields. Assess the accessibility of these forms and coordinate with your team to apply the necessary software updates or implement configuration changes to restrict unauthorized file uploads while remediation plans are finalized.

References