The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
| CVE | [CVE-2026-87796]( · [CVE.org]( |
| CWE | [CWE-434]( |
| CVSS | **Critical: 9.8** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` |
| Product | [Multi Uploader for Gravity Forms]( |
| Affected | all versions **through 1.1.9** (inclusive) |
| Patched | vendor patch — see references |
| Lab | `127.0.0.1` only · vendor/client disclosure pack, not a scanner |
The advisory names move_file. That is a private PHP method, not HTTP action=. The HTTP action is gfmu-plupload-submit. Chunked vs non-chunked is REQUEST[chunks]>1. PHP function names are not admin-ajax action=.
- **Router:** wp_ajax_nopriv_gfmu-plupload-submit → GFMUHandlePluploader::plupload_ajax_submit. Nonce field is REQUEST[nonce] for action gfmu-upload-nonce. Do not invent a different ajax action.
- **Notes:** CVE-2026-87796: chunked handleUpload (REQUEST chunks>1) copies the assembled file with move_file BEFORE validateUploadedFile. Non-chunked validates first. Without a field, enable_chunked is false and toBytes(ini 2M) 1 (GFMU_FileUploader.php:231-319)`
- `move_file copy then unlink tmp (GFMU_FileUploader.php:319, 545-560)`
- `validateUploadedFile only AFTER the file is already at $target (322) — unlike non-chunked which validates first (375)`
- `GET /wp-content/uploads/gfmu-uploads-tmp/ for POC_WITNESS_87796`
- WordPress with gf-multi-uploader 1.1.9 active
- Lab GF stub mu-plugin so GFForms exists and nopriv AJAX registers
- Public page slug gfmu-lab-nonce with GFMU_NONCE= for uid 0
- Do not pass currentFormID (no real Gravity Forms forms)
HTTP GET of the uploaded file returns the unique string POC_WITNESS_87796. JSON result=success plus that GET is SUCCESS. Theme HTML, admin-ajax 0, or Server error. nonce fail is not it.
- invalid extension without a file that still GETs the witness
- uploading an allowed jpg/png that is not the arbitrary-type sink
**Do this first:** Apply the vendor patch for **Multi Uploader for Gravity Forms**. See references.
- Re-run `CVE-2026-87796-Abraxas-Labs.py` against the patched build: the mapped witness must **not** appear.
- Confirm the vendor advisory / changeset in the deployed tree (see references).
- Disable or isolate the affected component.
- Hunt for the witness condition on production (new privileged users, unexpected files, injected rows — whatever this CVE's map names).
Target **only** ` (or the loopback you bound). Do not point this script at the internet.
Success is the **witness** above in the response body. Generic 200 HTML is not it.
- [CVE-2026-87796 · NVD](
- [CVE-2026-87796 · CVE.org](
- [plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/GFMUAddon.class.php#L125](
- [plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMUHandlePluploader.class.php#L257](
- [plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L319](
- [plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L322](
- [plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L560](
- [
- [github.com/advisories/GHSA-h7vp-g8q2-89c8](
- [nvd.nist.gov/vuln/detail/CVE-2026-87796](
- Plugin directory: [gf-multi-uploader](
- Trac browser: [plugins.trac.wordpress.org/gf-multi-uploader](
- SVN tags: [plugins.svn.wordpress.org/gf-multi-uploader](
- Abraxas Labs: [abraxaslabs.tech]( · [github.com/abraxas]( · [@abraxas_null](
- input: `
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- sh1zen Multi Uploader for Gravity Forms 0 affected
-
-
-
-
-
-
-
-
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload...
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
This pack is for **the vendor, the site owner, and licensed labs**. The script talks to `127.0.0.1`. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
