CVE-2014-4972: Malicious File Upload
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravityforms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4972?
CVE-2014-4972 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2014-4972?
To fix CVE-2014-4972, upgrade the Gravity Upload Ajax plugin to version 1.2 or later.
What types of files can be uploaded that exploit CVE-2014-4972?
Attackers can exploit CVE-2014-4972 by uploading files with executable extensions like .php.
Can CVE-2014-4972 affect my website if I’m using an unaffected version?
If you are using a version of the Gravity Upload Ajax plugin higher than 1.1, you are not affected by CVE-2014-4972.
How can I prevent CVE-2014-4972 in the future?
To prevent vulnerabilities like CVE-2014-4972, regularly update all plugins and monitor for security advisories.