Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f7m4-f638-5p2j

Опубликовано: 24 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

EPSS

Процентиль: 28%
0.001
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
около 2 месяцев назад

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

EPSS

Процентиль: 28%
0.001
Низкий

6.8 Medium

CVSS3