CVE-2025-23921

CVSS 3.1 Score 9 of 10 (high)

Details

Published Jan 22, 2025
CWE ID 434

Summary

CVE-2025-23921 is a newly disclosed vulnerability affecting the NotFound Multi Uploader plugin for Gravity Forms. This issue permits an unrestricted file upload, enabling attackers to upload a malicious web shell to a web server. The vulnerability exists in versions of the Multi Uploader plugin from n/a through 1.1.3. Successful exploitation of this flaw can result in arbitrary code execution and potential site compromise. Users of the affected plugin are urged to update to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share