Wordfence Argus Finds Unauthenticated Arbitrary File Upload Vulnerability in Gravity Forms
Brief
On August 9th, 2026, Wordfence Argus, created by the Wordfence Threat Intelligence team, discovered an Arbitrary File Upload vulnerability in Gravity Forms, a WordPress plugin estimated to have more than one million active installations. This high-severity vulnerability makes it possible for unauthenticated threat actors to write files with attacker-selected extensions to a public temporary upload directory.
This can lead to remote code execution.
We discovered this vulnerability with the help of Wordfence Argus , which we covered in a separate post . Our mission is to secure WordPress through defense in depth, which is why we invest in quality vulnerability research and work closely with plugin vendors to ensure vulnerabilities are addressed before they can be widely exploited.
