PT-2026-94156 · WordPress · Multi Uploader For Gravity Forms

CVE-2026-87796

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multi Uploader for Gravity Forms versions prior to 1.2.0
Description Insufficient file type validation during chunked upload handling in the move file() function allows unauthenticated attackers to upload arbitrary files to the server. This flaw can lead to remote code execution, which is the ability of an attacker to execute malicious commands on a remote machine over a network.
Recommendations As a temporary workaround, consider restricting the use of the move file() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87796

Affected Products

Multi Uploader For Gravity Forms