CVE-2025-12352
CRITICAL EXPLOITEDGravity Forms <= 2.9.20 - Unauthenticated Arbitrary File Upload via copy_post_image()
Title source: llmExploitation Summary
CVE-2025-12352 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including HORKimhab.
AI-analyzed exploit summary The repository contains a placeholder markdown file for CVE-2025-12352, describing an unauthenticated arbitrary file upload vulnerability in Gravity Forms <= 2.9.20 due to missing file type validation in the `copy_post_image()` function. No exploit code or technical proof-of-concept is provided.
Description
The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function in all versions up to, and including, 2.9.20. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. This only impacts sites that have allow_url_fopen set to `On`, the post creation form enabled along with a file upload field for the post
Exploits (1)
The repository contains a placeholder markdown file for CVE-2025-12352, describing an unauthenticated arbitrary file upload vulnerability in Gravity Forms <= 2.9.20 due to missing file type validation in the `copy_post_image()` function. No exploit code or technical proof-of-concept is provided.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H