## Overview
The Gravity Forms plugin for WordPress has a critical vulnerability identified as CVE-2026-84434. This affects all versions up to and including 3.1.0.4. The flaw allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution.
## Technical Details
The vulnerability arises from a mismatch between the field validation pipeline and the file persistence pipeline. Specifically, hidden file upload fields can bypass extension validation. When a file is rejected, its intact upload state is still passed to the `upload_file()` function without re-validation. This allows attackers to exploit forms that contain a File Upload field set to 'Hidden'.
## Impact
Exploitation of this vulnerability can lead to unauthorized file uploads, which may include executable files. If successful, this could enable remote code execution on the affected server. The vulnerability is reachable by any unauthenticated user on publicly accessible forms that meet the conditions.
## Mitigation
Defenders should immediately update Gravity Forms to the latest version. Users should also review their forms to ensure that no file upload fields are set to 'Hidden'. Regular audits of installed plugins and their configurations can help prevent exploitation of similar vulnerabilities in the future.
CSURFACE Threat Sensor