CVE-2025-13407
MEDIUMGravity Forms < 2.9.23.1 - Remote Code Execution via Chunked Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-13407. PoCs published by xxconi.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-13407, targeting Gravity Forms < 2.9.23.1. The exploit leverages unauthenticated arbitrary file upload via chunked upload manipulation to achieve remote code execution (RCE).
Description
The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.
Exploits (1)
This repository contains a functional exploit for CVE-2025-13407, targeting Gravity Forms < 2.9.23.1. The exploit leverages unauthenticated arbitrary file upload via chunked upload manipulation to achieve remote code execution (RCE).
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N