THREAT OPS › Threat News › Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
<p>On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upl
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 01c3929fe6b851d3cf7bda3c0215f691md5
- f97767e14ecb84ebfb6efdeaad2ee129md5
- CVE-2026-19513cve
- https://www.cve.org/CVERecord?id=CVE-2026-19513url
- https://docs.gravityforms.com/gravityforms-change-log/url
- www.gravatar.comdomain