Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms 

SecurityVendor

On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upload directory. This can lead to remote code execution.
The post Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms appeared first on Wordfence.WordfenceRead More