CVE-2026-84434 — Gravity Forms ≤ 3.1.0.4 Unauthenticated Arbitrary File Upload
Unauthenticated arbitrary file upload in **Gravity Forms** (≤ 3.1.0.4) abusing a hidden **File Upload** field (`upload_file`).
#wordpress#gravity-forms#file-upload#unauthenticated
Description
Overview
CVE-2026-84434 is a critical unauthenticated arbitrary file upload in Gravity Forms (≤ 3.1.0.4). A hidden or improperly protected File Upload field (upload_file) allows remote attackers to upload malicious files without logging in.
Impact
Unrestricted upload commonly leads to webshell deployment and full server compromise under the web server user.
Remediation
Upgrade Gravity Forms immediately. Audit uploaded media and form entries for unexpected binaries.
Legal and ethical use
Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.
References
- Look up the CVE ID on NVD and the CVE Program for official records.
- Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.