CVE-2025-23921 CRITICAL

CVE-2025-23921: WordPress Multi Uploader for Gravity Forms plugin <= 1.1.3 - Arbitrary File Upload vulnerability

Vendor Sh1Zen
Product Multi Uploader for Gravity Forms
Weakness CWE-434 · Unrestricted file upload
Published January 22, 2025
Last update May 11, 2026

CVSS base score

9.0/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3.

Explanation of Vulnerability in Simple Terms

02Summary

Multi Uploader for Gravity Forms versions 1.1.3 and earlier allow unauthenticated attackers to upload arbitrary files to the site. The vulnerability requires specific conditions to exploit but can lead to complete compromise of the site, including data theft, modification, and service disruption. Site administrators should update immediately to a patched version.

What an attacker can do

03Attacker Capabilities

Upload arbitrary files to the site without authentication, potentially executing code or stealing data.

Potential impact on your site

04Site Impact

Attackers can upload malicious files, run code on your site, steal data, or take the site offline.

Conditions required to exploit

05Prerequisites

Network access to the site; specific attack complexity conditions must be met.

Key dates

06Disclosure timeline

January 22, 2025 CVE published
May 11, 2026 Record updated

Related vulnerabilities

08Related CVE