CVE-2025-12352: Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via 'copy_post_image'
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copypostimage() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allowurlfopen set to On, the post creation form enabled along with a file upload field for the post
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12352?
CVE-2025-12352 is considered a high severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2025-12352?
To fix CVE-2025-12352, update the Gravity Forms plugin to version 2.9.21 or higher.
What impact does CVE-2025-12352 have on my WordPress site?
CVE-2025-12352 allows unauthenticated attackers to upload arbitrary files, potentially leading to further attacks on your site.
Is my site affected by CVE-2025-12352?
If you are using Gravity Forms version 2.9.20 or earlier, your site is vulnerable to CVE-2025-12352.
Who is at risk from CVE-2025-12352?
Any website using vulnerable versions of the Gravity Forms plugin is at risk of exploitation from CVE-2025-12352.