Multi Uploader for Gravity Forms

Multi Uploader for Gravity Forms has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 9.6, and the most serious one scores 9.8 out of 10. Severity breakdown: 3 critical and 0 high. 2025 was the busiest year with 2 disclosures.

The most common weakness is Missing Authorization, behind 1 of the records (33%). Other recurring categories include Path Traversal, Unrestricted Upload Of File With Dangerous Type.

Every one of the 3 issues recorded for Multi Uploader for Gravity Forms has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Multi Uploader for Gravity Forms is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSCritical
9.6/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Multi Uploader for Gravity Forms vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-14344

Multi Uploader for Gravity Forms <= 1.1.7 - Unauthenticated Arbitrary File Deletion

Read the full analysis

Vulnerability Records

3 records
Multi Uploader for Gravity Forms banner
Latestv1.1.9

Multi Uploader for Gravity Forms

sh1zen

Author

sh1zen

0.0(0)
0/100
Last Updated
2026-04-08 (5mo ago)
Active Installs
20+
Downloads
4,874
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 6.9.7
Created
2021-09-03 (5y ago)

This is an advanced upload plugin for those who need a little more than the default multi file upload of Gravity Forms. The plugin options page provides you with granular control over many Plupload parameters from file extension filters to chunked uploading and runtimes. All files are uploaded to the WordPress media library on successful form submission making for easy access and management. FEATURES Safety: validation of both file extension and mime type. Privacy: filenames changed once added to media library. Advanced Customization: many options and many hooks to modify any plugin rule. Large File Support: enabled by chunked file uploads. Media library integration: all files are uploaded to the WordPress media library on successful form submission making for easy access and management. Entry list creation integration: A list of all correctly uploaded files, with relative link. DONATIONS This plugin is free and always will be, but if you are feeling generous and want to show your support, you can buy me a beer or coffee here, I will really appreciate it. Hooks Filters: * &#8216;gfmu_plugin_locale’ * &#8216;gfmu_before_attach_uploads’ * &#8216;gfmu_maybe_insert_attachment’ * &#8216;gfmu_server_validation_args’ * &#8216;gfmu_insert_attachment_args’ * &#8216;gfmu_field_options’ * &#8216;gfmu_save_entry’

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C