CVE · High

CVE-2026-12997 — Gravity Forms [gravityforms] < 2.10.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12997 Gravity Forms [gravityforms] < 2.10.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.10.5 2.10.5 2026-07-15

CVE-2026-12997

A security flaw exists in Gravity Forms for WordPress, affecting versions up to 2.10.4, where an attacker can access server files via the 'gform_uploaded_files' parameter. This vulnerability allows unauthorized individuals to read sensitive data stored on the server, posing a risk if forms are publicly accessible and do not enforce login requirements.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.