CVE · High

CVE-2025-12974 — Gravity Forms [gravityforms] < 2.9.22

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12974 Gravity Forms [gravityforms] < 2.9.22 Unrestricted Upload of File with Dangerous Type High 8.1 < 2.9.22 2.9.22 2025-11-17

CVE-2025-12974

The Gravity Forms plugin for WordPress has a security flaw in its legacy chunked upload mechanism that allows unauthenticated attackers to upload executable files without proper validation, specifically targeting .phar files which are not blocked by the extension blacklist. This vulnerability enables attackers to potentially execute malicious code on the server if the web server is configured to process these files as PHP scripts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.