CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5810

As cited

Copy frozen at (site build).

vulnerabilities

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

Wordfence discovered CVE-2026-19513, an unauthenticated arbitrary file upload vulnerability in Gravity Forms plugin (versions up to 3.0.2) affecting over one million WordPress installations. The flaw allows attackers to upload PHP or HTML polyglots to a public temporary directory through a state hash confusion issue in the chunked upload handler, potentially leading to remote code execution on NGINX-based servers or cross-site scripting on Apache with .htaccess protection. Gravity Forms released patched version 3.0.3 on August 20, 2026, implementing server-generated temporary filenames, domain-separated HMAC tokens, and stricter validation.

Why it matters: WordPress site operators running Gravity Forms up to version 3.0.2 with public multi-file upload forms face immediate remote code execution risk from unauthenticated attackers; update to version 3.0.3 or newer urgently. Free Wordfence users receive firewall protection on September 12, 2026, but paid customers have had it since August 13, 2026.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms

Wordfence discovered CVE-2026-19513, an unauthenticated arbitrary file upload vulnerability in Gravity Forms plugin (versions up to 3.0.2) affecting over one million WordPress installations. The flaw allows attackers to upload PHP or HTML polyglots to a public temporary directory through a state hash confusion issue in the chunked upload handler, potentially leading to remote code execution on NGINX-based servers or cross-site scripting on Apache with .htaccess protection. Gravity Forms released patched version 3.0.3 on August 20, 2026, implementing server-generated temporary filenames, domain-separated HMAC tokens, and stricter validation.

Why it matters: WordPress site operators running Gravity Forms up to version 3.0.2 with public multi-file upload forms face immediate remote code execution risk from unauthenticated attackers; update to version 3.0.3 or newer urgently. Free Wordfence users receive firewall protection on September 12, 2026, but paid customers have had it since August 13, 2026.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary