
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13407 is an unauthenticated arbitrary file upload vulnerability in the Gravity Forms WordPress plugin that enables remote code execution (RCE). The flaw affects all versions of Gravity Forms before 2.9.23.1 and stems from insufficient file type validation in the plugin's chunked upload functionality, allowing attackers to upload PHP files to the server. It was published on December 24, 2025, with a CVSS v3.1 base score of 6.8 (Medium), assessed by CISA-ADP (WPScan, Red Hat CVE).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type). The Gravity Forms plugin's chunked upload endpoint (/?gf_page=upload) fails to properly validate or restrict file extensions, allowing PHP files to be submitted through multi-file upload form fields without authentication. Exploitation requires the attacker to first discover or enumerate the server-side upload path where the file is stored before executing it. A public proof-of-concept Python script has been published by WPScan demonstrating the full upload chain using the requests and BeautifulSoup libraries (WPScan).
Successful exploitation allows an unauthenticated attacker to upload arbitrary PHP files to the WordPress server and achieve remote code execution by accessing the uploaded file's URL. This can result in full server compromise, including unauthorized access to sensitive data (high confidentiality impact), modification or deletion of site content and files (high integrity impact), and potential lateral movement within the hosting environment. Availability is not directly impacted by the upload itself, but post-exploitation actions could disrupt service (WPScan, Red Hat CVE).
A public proof-of-concept exploit script is available via WPScan, lowering the barrier for exploitation significantly. The vulnerability is exploitable without authentication, requiring only that the target site has a Gravity Forms page with a multi-file upload field enabled and that the attacker can enumerate the upload path. The EPSS score is approximately 0.058% (0.000580), suggesting currently low observed exploitation probability. No CISA KEV catalog listing or confirmed in-the-wild exploitation campaigns have been reported as of the available data (WPScan, Feedly).
.gform_fileupload_multifile CSS class in the page HTML).id attribute./?gf_page=upload with a PHP webshell (e.g., phpinfo.php or a reverse shell) as the file payload, using the chunked upload mechanism. The plugin fails to block PHP file extensions at this stage./wp-content/uploads/gravity_forms/), or directory enumeration tools./?gf_page=upload with .php file extensions in the multipart body; outbound connections from the web server process to unknown external IPs following file upload activity.*.php, shell.php, phpinfo.php) present in Gravity Forms upload directories such as /wp-content/uploads/gravity_forms/; newly created files with webshell patterns (e.g., eval(, base64_decode(, system(, passthru()./?gf_page=upload with unusual file names or content types; subsequent GET requests to PHP files within the Gravity Forms upload directory.php, /bin/sh, curl, wget) not associated with normal WordPress operations.The vendor has released Gravity Forms version 2.9.23.1, which addresses the file upload validation flaw. All sites running Gravity Forms prior to this version should update immediately via the WordPress admin dashboard or by downloading the patched plugin directly from the vendor. As a temporary workaround, administrators can disable any forms containing multi-file upload fields until the patch is applied, or restrict access to the /?gf_page=upload endpoint via web server rules (e.g., .htaccess or nginx configuration) (WPScan, Red Hat CVE).
WPScan published the vulnerability disclosure along with a full proof-of-concept script on December 24, 2025, providing detailed technical context for the security community. The vulnerability was also noted by INCIBE-CERT (Spain's national cybersecurity incident response team) and tracked by ENISA's EUVD database (EUVD-2025-205034). Community aggregators including Vulners, CIRCL Vulnerability Lookup, and Offseq Radar indexed the CVE shortly after disclosure, indicating moderate security community interest (WPScan, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."