CVE-2025-12352 describes a critical arbitrary file upload vulnerability in the Gravity Forms WordPress plugin, affecting all versions up to and including 2.9.20. This flaw, stemming from missing file type validation in the copy_post_image() function, allows unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution. The vulnerability is rated 9.8 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Exploitation is contingent on allow_url_fopen being enabled and a post creation form with a file upload field being active. Currently, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.9.20CPE match | cpe:2.3:a:gravityforms:gravity_forms:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.