CVE-2014-6446
Gravity Forms <1.5.11 - RCE
Title source: llmDescription
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/34925
metasploit
WORKING POC
EXCELLENT
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_infusionsoft_upload.rb
References (5)
Scores
EPSS
0.8221
EPSS Percentile
99.2%
Details
CWE
CWE-94
Status
published
Products (18)
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.3
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.4
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.4.1
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.4.2
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.5
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.6
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.7
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.7.1
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.7.2
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms
1.5.8
... and 8 more
Published
Sep 26, 2014
Tracked Since
Feb 18, 2026