CVE-2014-6446

Gravity Forms <1.5.11 - RCE

Title source: llm

Description

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/34925
metasploit WORKING POC EXCELLENT
by g0blin, us3r777 <[email protected]> · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_infusionsoft_upload.rb

Scores

EPSS 0.8221
EPSS Percentile 99.2%

Details

CWE
CWE-94
Status published
Products (18)
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.3
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.4
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.4.1
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.4.2
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.5
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.6
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.7
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.7.1
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.7.2
infusionsoft_gravity_forms_project/infusionsoft_gravity_forms 1.5.8
... and 8 more
Published Sep 26, 2014
Tracked Since Feb 18, 2026