Detects Gravity Forms installations vulnerable to unauthenticated arbitrary file upload leading to remote code execution. In all versions up to and including 3.1.0.4, a mismatch between the field-validation pipeline and the file-persistence pipeline lets a File Upload field whose Visibility is set to Hidden bypass extension validation. A file that was rejected during validation keeps its intact upload state and is passed to upload_file() with no re-validation, so an unauthenticated attacker can POST a .php web shell to the async upload endpoint (admin-ajax.php action=gf_upload_files) on any public form containing a Hidden File Upload field. The verifier uploads a PHP payload that prints a per-run canary computed from two constants, then fetches the persisted file and confirms the arithmetic result came back, proving server-side code execution rather than mere file persistence. CVSS 9.8. Upgrade to Gravity Forms 3.1.0.5 or later.
Is your app exploitable through CVE-2026-84434?
Scan your domain free