THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-87796 (CRITICAL 9.8) — The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for una

[NVD] CVE-2026-87796 (CRITICAL 9.8) — The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for una

mednvdPublished 2026-09-17

CVE-2026-87796 CVSS: 9.8 CRITICAL Published: 2026-09-17T05:17:02.123

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files o

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87796