PT-2026-68025 · WordPress · Multi Uploader For Gravity Forms

CVE-2026-5581

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multi Uploader for Gravity Forms versions prior to 1.1.9
Description Unauthenticated attackers can permanently delete any WordPress media attachment by providing its attachment ID. This issue occurs because the plupload ajax delete file() function, registered via wp ajax nopriv gfmu delete file, lacks necessary capability checks. Additionally, the nonce used for Cross-Site Request Forgery (CSRF) protection—a security token used to prevent unauthorized commands from being transmitted from a user that the web application trusts—is exposed on public pages containing a multi-uploader form field through the GFMU options JavaScript object.
Recommendations Update Multi Uploader for Gravity Forms to a version newer than 1.1.8.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5581

Affected Products

Multi Uploader For Gravity Forms