CVE-2026-84434 is an unauthenticated arbitrary file-upload vulnerability in the Gravity Forms plugin for WordPress through version 3.1.0.4. The flaw is in the handling of hidden File Upload fields: a mismatch between the field-validation and file-persistence pipelines permits extension validation to be bypassed. The upload state of a rejected file can subsequently reach the upload_file() function without re-validation, allowing persistence of potentially executable content. Affected deployments can therefore permit remote code execution when uploaded content is executable by the web server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This five-file Python repository contains a standalone scanner and exploit for CVE-2026-84434, an alleged unauthenticated unrestricted file-upload flaw in WordPress Gravity Forms versions through 3.1.0.4. The primary entry point, poc.py (Python 3), uses requests and urllib3 to normalize targets, suppress TLS-verification warnings, fingerprint the Gravity Forms plugin and version from plugin files/assets, crawl common public form paths, and parse rendered forms for hidden file-upload controls. It supports single-target and concurrent mass operation, including plain URL, FOFA-style CSV, and prior JSONL candidate input. In exploit mode, it fills required visible fields with placeholders and performs a multipart Gravity Forms submission using fields such as gform_submit and is_submit_<form-id>, placing the selected file on the discovered hidden input (input_<form-id>_<field-id>). The default content is a harmless text marker, while --payload-file permits an arbitrary local file. The tool emits full JSONL results and separate candidate/hit lists. README.md documents operation and limitations, requirements.txt lists requests and urllib3, and targets.example.txt provides a placeholder target. No exploit framework integration, bundled shell, persistence mechanism, or direct RCE routine is present; executable uploaded content would rely on unsafe target-server handling of the Gravity Forms upload directory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated arbitrary file-upload vulnerability in the WordPress Gravity Forms plugin. Hidden upload fields bypass validation, allowing attackers to upload executable files and obtain remote code execution.
An unauthenticated arbitrary-file-upload vulnerability in the Gravity Forms WordPress plugin through version 3.1.0.4. A validation-versus-file-persistence pipeline mismatch permits hidden upload fields to bypass extension validation; potentially executable files can then be uploaded, enabling remote code execution when a publicly accessible form contains a hidden File Upload field.
An unauthenticated arbitrary-file-upload vulnerability in the Gravity Forms WordPress plugin through version 3.1.0.4. A mismatch between validation and persistence permits hidden upload fields to bypass extension validation; uploaded executable files may enable remote code execution on publicly accessible forms configured with a hidden File Upload field.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.