CVE-2025-13407: GravityForms < 2.9.23.1 - Unauthenticated Arbitrary File Upload
The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13407?
CVE-2025-13407 has a critical severity rating due to its potential for remote code execution through vulnerable file uploads.
How do I fix CVE-2025-13407?
To fix CVE-2025-13407, update the Gravity Forms WordPress plugin to version 2.9.23.1 or later.
What types of files can be uploaded that exploit CVE-2025-13407?
CVE-2025-13407 allows attackers to upload dangerous PHP files, which can lead to remote code execution.
Which versions of Gravity Forms are affected by CVE-2025-13407?
Gravity Forms versions before 2.9.23.1 are affected by CVE-2025-13407.
Who is at risk from CVE-2025-13407?
Websites using vulnerable versions of the Gravity Forms plugin are at risk from CVE-2025-13407.