POCBIT

CVE-2026-84434 — Gravity Forms ≤ 3.1.0.4 Unauthenticated Arbitrary File Upload

Unauthenticated arbitrary file upload in **Gravity Forms** (≤ 3.1.0.4) abusing a hidden **File Upload** field (`upload_file`).

#wordpress#gravity-forms#file-upload#unauthenticated

CVE:

CVE-2026-84434

Date:

2026-09-25

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-84434 is a critical unauthenticated arbitrary file upload in Gravity Forms (≤ 3.1.0.4). A hidden or improperly protected File Upload field (upload_file) allows remote attackers to upload malicious files without logging in.

Impact

Unrestricted upload commonly leads to webshell deployment and full server compromise under the web server user.

Remediation

Upgrade Gravity Forms immediately. Audit uploaded media and form entries for unexpected binaries.

Legal and ethical use

Use bundled tools only on WordPress sites you own or have written authorization to test. Unauthorized scanning or exploitation is illegal in most jurisdictions.

References

  • Look up the CVE ID on NVD and the CVE Program for official records.
  • Apply vendor/plugin updates from the official repository or vendor advisory before relying on any PoC.