Логотип exploitDog
bind:CVE-2025-13407
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-13407

Количество 2

Количество 2

nvd логотип

CVE-2025-13407

около 2 месяцев назад

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-f7m4-f638-5p2j

около 2 месяцев назад

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-13407

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-f7m4-f638-5p2j

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

CVSS3: 6.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу