CVE-2025-14344: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14344 is an arbitrary file deletion vulnerability in the Multi Uploader for Gravity Forms WordPress plugin, caused by insufficient file path validation in the plupload_ajax_delete_file function. It affects all plugin versions up to and including 1.1.7, and allows unauthenticated remote attackers to delete arbitrary files on the server. The vulnerability was published on December 12, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is a path traversal flaw (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) in the plupload_ajax_delete_file function within GFMUHandlePluploader.class.php. The function fails to properly validate or sanitize the file path supplied by the user before performing file deletion operations, allowing an attacker to supply path traversal sequences (e.g., ../../) to reference files outside the intended upload directory. Because no authentication is required to invoke this function, any remote attacker can trigger arbitrary file deletion without credentials (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an unauthenticated attacker to delete any file accessible to the web server process on the host, including critical WordPress configuration files (e.g., wp-config.php), core application files, or system files. This can result in complete data loss, disruption or total takedown of the website, and potential exposure of sensitive information. Deletion of configuration files may also enable secondary attacks such as site reinstallation hijacking or privilege escalation (Wordfence).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.138%, indicating a low current probability of exploitation in the near term. The vulnerability has been detected by Qualys (detection ID 530763) (Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Multi Uploader for Gravity Forms plugin (versions ≤ 1.1.7) using tools like WPScan, Shodan, or by inspecting plugin directories at /wp-content/plugins/gf-multi-uploader/.
  2. Identify the vulnerable endpoint: Locate the AJAX handler for plupload_ajax_delete_file, typically accessible via WordPress's admin-ajax.php endpoint with the appropriate action parameter.
  3. Craft malicious request: Send an unauthenticated HTTP POST request to wp-admin/admin-ajax.php with the action set to the delete file handler and a file path parameter containing path traversal sequences (e.g., ../../wp-config.php) to target files outside the upload directory.
  4. Achieve arbitrary file deletion: The server processes the unsanitized path and deletes the targeted file, which can include critical files such as wp-config.php, disabling the site or enabling a reinstallation attack (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual unauthenticated POST requests to wp-admin/admin-ajax.php with file deletion action parameters and path traversal sequences (e.g., ../) in file path fields.
  • Logs: Web server access logs showing repeated POST requests to admin-ajax.php from unknown IPs with suspicious file or path parameters; WordPress debug logs indicating unexpected file operation errors.
  • File System: Unexpected absence of critical files such as wp-config.php, WordPress core files, or plugin/theme files; timestamps of file deletions correlating with suspicious request times.
  • Process: Unexpected WordPress reinstallation prompts or database connection errors following file deletions, which may indicate wp-config.php was removed.

Mitigation and workarounds

The recommended remediation is to update the Multi Uploader for Gravity Forms plugin to a version beyond 1.1.7, which addresses the insufficient path validation (Wordfence). If an immediate update is not possible, administrators should temporarily disable the plugin to eliminate the attack surface. Additional hardening measures include implementing strict file system permissions to limit what the web server process can delete, and monitoring server and WordPress logs for suspicious unauthenticated AJAX requests targeting file deletion endpoints.

Community reactions

Wordfence published the vulnerability in their weekly WordPress vulnerability report for December 8–14, 2025, and it was included in the CISA vulnerability bulletin for the relevant period (Wordfence Blog, CISA Bulletin). The vulnerability was also noted by security aggregators including Qualys, VulnDB, and CVEFeed. No significant independent researcher commentary or notable social media discussion beyond automated CVE tracking posts has been observed.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management