THREATOPS
THREAT OPSThreat News › Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

medwordfencePublished 2026-09-01

<p>On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upl

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/09/wordfence-argus-finds-unauthenticated-arbitrary-file-upload-vulnerability-in-gravity-forms/