top of page
perceptive_background_267k.jpg

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. Th…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 09:07:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2026-5581 affects the Multi Uploader for Gravity Forms WordPress plugin in all versions up to and including 1.1.8. The vulnerability allows unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID. The root cause is a missing capability check in the plupload_ajax_delete_file() function, registered via the wp_ajax_nopriv_gfmu_delete_file hook, which allows unauthenticated AJAX calls. A nonce intended for CSRF protection is inadvertently exposed on any public-facing page containing a multi-uploader form field through the GFMU_options JavaScript object. Exploitation could lead to complete destruction of a site's media library. No authentication is required, making this a critical unauthenticated vulnerability. A patch is available in the plugin trunk repository.

Technical details

Mitigation steps:

Affected products:

Multi Uploader for Gravity Forms WordPress Plugin <= 1.1.8

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page