CVE · Critical

CVE-2025-12352 — Gravity Forms [gravityforms] < 2.9.21

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12352 Gravity Forms [gravityforms] < 2.9.21 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 2.9.21 2.9.21 2025-11-06

CVE-2025-12352

A critical security flaw exists in Gravity Forms plugin versions up to 2.9.20, allowing unauthorized access to upload any type of file via the copy_post_image() function due to inadequate validation checks. This vulnerability can lead to remote code execution if exploited on servers with allow_url_fopen enabled and a post creation form configured with a file upload field. The issue specifically affects sites that have this configuration in place.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.