
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14344 is an arbitrary file deletion vulnerability in the Multi Uploader for Gravity Forms WordPress plugin, caused by insufficient file path validation in the plupload_ajax_delete_file function. It affects all plugin versions up to and including 1.1.7, and allows unauthenticated remote attackers to delete arbitrary files on the server. The vulnerability was published on December 12, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is a path traversal flaw (CWE-22: Improper Limitation of a Pathname to a Restricted Directory) in the plupload_ajax_delete_file function within GFMUHandlePluploader.class.php. The function fails to properly validate or sanitize the file path supplied by the user before performing file deletion operations, allowing an attacker to supply path traversal sequences (e.g., ../../) to reference files outside the intended upload directory. Because no authentication is required to invoke this function, any remote attacker can trigger arbitrary file deletion without credentials (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to delete any file accessible to the web server process on the host, including critical WordPress configuration files (e.g., wp-config.php), core application files, or system files. This can result in complete data loss, disruption or total takedown of the website, and potential exposure of sensitive information. Deletion of configuration files may also enable secondary attacks such as site reinstallation hijacking or privilege escalation (Wordfence).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.138%, indicating a low current probability of exploitation in the near term. The vulnerability has been detected by Qualys (detection ID 530763) (Qualys).
/wp-content/plugins/gf-multi-uploader/.plupload_ajax_delete_file, typically accessible via WordPress's admin-ajax.php endpoint with the appropriate action parameter.wp-admin/admin-ajax.php with the action set to the delete file handler and a file path parameter containing path traversal sequences (e.g., ../../wp-config.php) to target files outside the upload directory.wp-config.php, disabling the site or enabling a reinstallation attack (Wordfence, WordPress Trac).wp-admin/admin-ajax.php with file deletion action parameters and path traversal sequences (e.g., ../) in file path fields.admin-ajax.php from unknown IPs with suspicious file or path parameters; WordPress debug logs indicating unexpected file operation errors.wp-config.php, WordPress core files, or plugin/theme files; timestamps of file deletions correlating with suspicious request times.wp-config.php was removed.The recommended remediation is to update the Multi Uploader for Gravity Forms plugin to a version beyond 1.1.7, which addresses the insufficient path validation (Wordfence). If an immediate update is not possible, administrators should temporarily disable the plugin to eliminate the attack surface. Additional hardening measures include implementing strict file system permissions to limit what the web server process can delete, and monitoring server and WordPress logs for suspicious unauthenticated AJAX requests targeting file deletion endpoints.
Wordfence published the vulnerability in their weekly WordPress vulnerability report for December 8–14, 2025, and it was included in the CISA vulnerability bulletin for the relevant period (Wordfence Blog, CISA Bulletin). The vulnerability was also noted by security aggregators including Qualys, VulnDB, and CVEFeed. No significant independent researcher commentary or notable social media discussion beyond automated CVE tracking posts has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."