External risk intelligence

WordPress Multi Uploader Arbitrary File Upload Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-87796

The vulnerability exists in a WordPress plugin used for file uploads, which is typically integrated into public-facing web forms or contact pages. Because these forms are designed to be accessible to site visitors for data submission, the attack surface is commonly exposed to the public internet.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress plugin that handles file uploads. It allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution on the affected server. The main concern is confirming relevance and exposure of this plugin within our environment.

  • File upload flaw in a WordPress plugin.
  • Critical risk of unauthorized code execution.
  • Confirm plugin usage and assess exposure.

Attack Path

How an attacker could exploit the issue

Attackers can leverage a flaw in how the Multi Uploader for Gravity Forms plugin handles file uploads to place arbitrary files on a WordPress server. This occurs because the plugin does not properly validate file types during its chunked upload process, potentially allowing unauthenticated users to upload malicious files. If successful, this could lead to attackers executing their own code on the server.

  • Unauthenticated access required.
  • Vulnerable file upload component.
  • Potential for remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to upload arbitrary files to a WordPress site's server. When supported by the advisory, this could lead to the execution of malicious code, affecting the integrity and availability of the server.

  • Server files could be affected.
  • Arbitrary files can be uploaded.
  • Remote code execution is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The "Multi Uploader for Gravity Forms" WordPress plugin's arbitrary file upload vulnerability demands swift action from web administrators and potentially platform or infrastructure teams. The immediate first step is to identify all WordPress instances utilizing this plugin, determine their internet-facing exposure, and ascertain their business criticality. Once identified, the accountable owner should be engaged to plan remediation based on the assessed risk.

  • WordPress administrators own remediation.
  • Verify plugin usage and exposure.
  • Plan coordinated removal or updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Multi Uploader for Gravity Forms plugin?

It is an add-on for the Gravity Forms plugin in WordPress that enables users to upload multiple files through web forms. By extending the core functionality of Gravity Forms, it helps site owners collect documents or images from visitors. Because it processes incoming data streams from the public, it requires robust security checks to ensure only intended file types are saved to the server.

What does CWE-434 mean for CVE-2026-87796?

CWE-434 refers to Unrestricted Upload of File with Dangerous Type. In the context of this CVE, it means the plugin fails to properly verify or restrict the types of files being uploaded to the server. Because the validation is insufficient, the system might accept malicious files that an attacker can then trigger to run unauthorized commands, effectively bypassing security controls designed to prevent code execution.

How do attackers trigger this file upload bug?

An attacker triggers this vulnerability by sending a specifically crafted, unauthorized request to the plugin's chunked upload process. The flaw specifically exists in the move_file function, which handles these incoming file segments without checking the file's nature. Note that this does not require a user to be logged in, meaning any unauthenticated visitor can attempt the exploit if they can reach the form handling the upload.

Why is internet-facing access a concern here?

Halo Surface Signal indicates that this plugin is commonly integrated into public-facing contact forms or submission pages, making the attack surface readily available from the internet. Since the vulnerability allows unauthenticated access, any server running this plugin that is reachable via a browser is potentially exposed to remote attackers seeking to upload malicious files.

How should I respond if I use this plugin?

Begin by auditing your WordPress environment to identify if the Multi Uploader for Gravity Forms plugin is active on any of your sites. If found, evaluate the criticality of the site and its exposure to the public internet. Since this is a critical vulnerability, coordinate with your site owners to either remove the plugin or disable the affected upload functionality until a secure version is available and applied.

References