CVE & Vulnerabilities · September 21, 2026
CVE-2026-84434 affects the Gravity Forms WordPress plugin through version 3.1.0.4, where hidden upload fields can slip past extension checks because the field-validation step and the file-saving step don't agree with each other. A rejected upload's data can still reach the save function without being re-checked. Because no authentication is required to trigger it, attackers could potentially plant executable files on a vulnerable site.
// source: nvd.nist.gov ↗