CVE Database /
CVE-2025-12974
CVE · High
CVE-2025-12974 — Gravity Forms [gravityforms] < 2.9.22
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12974
|
Gravity Forms [gravityforms] < 2.9.22 |
Unrestricted Upload of File with Dangerous Type |
High
8.1
|
< 2.9.22
|
2.9.22 |
2025-11-17 |
—
|
CVE-2025-12974
The Gravity Forms plugin for WordPress has a security flaw in its legacy chunked upload mechanism that allows unauthenticated attackers to upload executable files without proper validation, specifically targeting .phar files which are not blocked by the extension blacklist. This vulnerability enables attackers to potentially execute malicious code on the server if the web server is configured to process these files as PHP scripts.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings