CVE-2025-13407

MEDIUM

Gravity Forms < 2.9.23.1 - Remote Code Execution via Chunked Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-13407. PoCs published by xxconi.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2025-13407, targeting Gravity Forms < 2.9.23.1. The exploit leverages unauthenticated arbitrary file upload via chunked upload manipulation to achieve remote code execution (RCE).

Description

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

Exploits (1)

github WORKING POC
by xxconi · pythonpoc
https://github.com/xxconi/CVE-2025-13407

This repository contains a functional exploit for CVE-2025-13407, targeting Gravity Forms < 2.9.23.1. The exploit leverages unauthenticated arbitrary file upload via chunked upload manipulation to achieve remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Gravity Forms < 2.9.23.1
No auth needed
Prerequisites: WordPress site with vulnerable Gravity Forms plugin · Access to the Gravity Forms file upload endpoint
mistral-large-3 · analyzed Jun 21, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/e09908fb-f5ad-45ca-8698-c0d596fd39cc/

Scores

CVSS v3 6.8
EPSS 0.0032
EPSS Percentile 24.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

Status published
Products (1)
Unknown/Gravity Forms < 2.9.23.1
Published Dec 24, 2025
Tracked Since Feb 18, 2026