Sploitus

CVE-2025-13407

3 known exploits for CVE-2025-13407

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

Affected products
Gravity Forms
Fix
Available
CVSS 3.1
6.8 MEDIUM
EPSS
0.4% (29th percentile)
NVD status
Deferred
Published
2025-12-24
CVE-2025-13407 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2025-13407

Proof-of-concept code and exploit modules indexed by Sploitus