THREAT OPS › Threat News › [NVD] CVE-2026-87796 (CRITICAL 9.8) — The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for una
[NVD] CVE-2026-87796 (CRITICAL 9.8) — The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for una
CVE-2026-87796 CVSS: 9.8 CRITICAL Published: 2026-09-17T05:17:02.123
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files o
Indicators of compromise
- CVE-2026-87796cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-87796