CVE-2025-13407
Last modified
CVE-2025-13407 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-13407?
How severe is CVE-2025-13407?
How do I fix CVE-2025-13407?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13400A vulnerability was detected in Tenda CH22 1.0.0.1. Affected…9.8
- CVE-2025-13401The Autoptimize plugin for WordPress is vulnerable to Stored…6.4
- CVE-2025-13403The Employee Spotlight – Team Member Showcase & Meet the Tea…4.3
- CVE-2025-13404The atec Duplicate Page & Post plugin for WordPress is vulne…5.3
- CVE-2025-13405The Ace Post Type Builder plugin for WordPress is vulnerable…5.3
- CVE-2025-13406NULL Pointer Dereference vulnerability in Softing Industrial…6.8
- CVE-2025-13408The Foxtool All-in-One: Contact chat button, Custom login, M…4.3
- CVE-2025-13409The Form Vibes – Database Manager for Forms plugin for WordP…4.9
- CVE-2025-1341A vulnerability, which was classified as problematic, was fo…8.1
- CVE-2025-13410A vulnerability has been found in Campcodes Retro Basketball…9.8
- CVE-2025-13411A vulnerability was found in Campcodes Retro Basketball Shoe…9.8
- CVE-2025-13412A vulnerability was determined in Campcodes Retro Basketball…6.1
Are you affected by CVE-2025-13407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
