CVE-2014-6446: Code Injection
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/codegenerator.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6446?
CVE-2014-6446 is rated as a high-severity vulnerability due to its potential to allow remote file uploads and execution of arbitrary PHP code.
How do I fix CVE-2014-6446?
To fix CVE-2014-6446, update the Infusionsoft Gravity Forms plugin to version 1.5.11 or later, which addresses the access restriction issue.
What type of attack does CVE-2014-6446 allow?
CVE-2014-6446 allows remote attackers to upload arbitrary files and execute arbitrary PHP code on the affected WordPress site.
Which versions of the Infusionsoft Gravity Forms plugin are affected by CVE-2014-6446?
CVE-2014-6446 affects Infusionsoft Gravity Forms plugin versions 1.5.3 through 1.5.10.
What should I do if I am using an affected version of the Infusionsoft Gravity Forms plugin?
If using an affected version of the Infusionsoft Gravity Forms plugin, immediately upgrade to the latest version to mitigate the vulnerability.