CVE-2026-5581 | sh1zen Multi Uploader for Gravity Forms Plugin up to 1.1.8 on WordPress Capability Check plupload_ajax_delete_file improper authorization

SecurityVulns

A vulnerability marked as critical has been reported in sh1zen Multi Uploader for Gravity Forms Plugin up to 1.1.8 on WordPress. This vulnerability affects the function plupload_ajax_delete_file of the component Capability Check. Performing a manipulation results in improper authorization.

This vulnerability was named CVE-2026-5581. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More