CVE-2025-12352

CRITICAL EXPLOITED

Gravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via copy_post_image()

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-12352 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HORKimhab.

AI-analyzed exploit summary The repository contains a placeholder markdown file for CVE-2025-12352, describing an unauthenticated arbitrary file upload vulnerability in Gravity Forms <= 2.9.20 due to missing file type validation in the `copy_post_image()` function. No exploit code or technical proof-of-concept is provided.

Description

The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allow_url_fopen set to `On`, the post creation form enabled along with a file upload field for the post

Exploits (1)

github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2025/12xxx/CVE-2025-12352.md

The repository contains a placeholder markdown file for CVE-2025-12352, describing an unauthenticated arbitrary file upload vulnerability in Gravity Forms <= 2.9.20 due to missing file type validation in the `copy_post_image()` function. No exploit code or technical proof-of-concept is provided.

Classification
Stub 95%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Gravity Forms plugin for WordPress <= 2.9.20
No auth needed
Prerequisites: allow_url_fopen set to `On` · Post creation form enabled with a file upload field
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0097
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-06-23
CWE
CWE-434
Status published
Products (1)
Gravity Forms/Gravity Forms < 2.9.20
Published Nov 07, 2025
Tracked Since Feb 18, 2026