Summary
Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution.
Take Action:
If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can't update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious activity.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)