


Perceptive Security
SOC/SIEM Consultancy

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. Th…
Published:
5 augustus 2026 om 00:00:00
Alert date:
5 augustus 2026 om 11:07:41
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2026-5581 affects the Multi Uploader for Gravity Forms WordPress plugin in all versions up to and including 1.1.8. The vulnerability allows unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID. The root cause is a missing capability check in the plupload_ajax_delete_file() function, registered via the wp_ajax_nopriv_gfmu_delete_file hook, which allows unauthenticated AJAX calls. A nonce intended for CSRF protection is inadvertently exposed on any public-facing page containing a multi-uploader form field through the GFMU_options JavaScript object. Exploitation could lead to complete destruction of a site's media library. No authentication is required, making this a critical unauthenticated vulnerability. A patch is available in the plugin trunk repository.
Technical details
Mitigation steps:
Affected products:
Multi Uploader for Gravity Forms WordPress Plugin <= 1.1.8
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5581
https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/GFMUAddon.class.php#L131
https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/inc/GFMUHandlePluploader.class.php#L66
https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/GFMUAddon.class.php#L131
https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/inc/GFMUHandlePluploader.class.php#L66
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3501985%40gf-multi-uploader%2Ftrunk&old=3421317%40gf-multi-uploader%2Ftrunk&sfp_email=&sfph_mail=
https://www.wordfence.com/threat-intel/vulnerabilities/id/16dca898-1a98-4e0b-8f48-dc01ba2dc4e6?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
