PT-2026-68025 · WordPress · Multi Uploader For Gravity Forms
CVE-2026-5581
·
Published
2026-08-05
·
Updated
2026-08-05
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Multi Uploader for Gravity Forms versions prior to 1.1.9
Description
Unauthenticated attackers can permanently delete any WordPress media attachment by providing its attachment ID. This issue occurs because the
plupload ajax delete file() function, registered via wp ajax nopriv gfmu delete file, lacks necessary capability checks. Additionally, the nonce used for Cross-Site Request Forgery (CSRF) protection—a security token used to prevent unauthorized commands from being transmitted from a user that the web application trusts—is exposed on public pages containing a multi-uploader form field through the GFMU options JavaScript object.Recommendations
Update Multi Uploader for Gravity Forms to a version newer than 1.1.8.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multi Uploader For Gravity Forms