As cited
Copy frozen at (site build).
vulnerabilities
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
Wordfence discovered CVE-2026-19513, an unauthenticated arbitrary file upload vulnerability in Gravity Forms plugin (versions up to 3.0.2) affecting over one million WordPress installations. The flaw allows attackers to upload PHP or HTML polyglots to a public temporary directory through a state hash confusion issue in the chunked upload handler, potentially leading to remote code execution on NGINX-based servers or cross-site scripting on Apache with .htaccess protection. Gravity Forms released patched version 3.0.3 on August 20, 2026, implementing server-generated temporary filenames, domain-separated HMAC tokens, and stricter validation.
Why it matters: WordPress site operators running Gravity Forms up to version 3.0.2 with public multi-file upload forms face immediate remote code execution risk from unauthenticated attackers; update to version 3.0.3 or newer urgently. Free Wordfence users receive firewall protection on September 12, 2026, but paid customers have had it since August 13, 2026.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
Wordfence discovered CVE-2026-19513, an unauthenticated arbitrary file upload vulnerability in Gravity Forms plugin (versions up to 3.0.2) affecting over one million WordPress installations. The flaw allows attackers to upload PHP or HTML polyglots to a public temporary directory through a state hash confusion issue in the chunked upload handler, potentially leading to remote code execution on NGINX-based servers or cross-site scripting on Apache with .htaccess protection. Gravity Forms released patched version 3.0.3 on August 20, 2026, implementing server-generated temporary filenames, domain-separated HMAC tokens, and stricter validation.
Why it matters: WordPress site operators running Gravity Forms up to version 3.0.2 with public multi-file upload forms face immediate remote code execution risk from unauthenticated attackers; update to version 3.0.3 or newer urgently. Free Wordfence users receive firewall protection on September 12, 2026, but paid customers have had it since August 13, 2026.
- Source published
- First seen by Cybersecurity Tracker