CVE-2026-5581 (matched: wordpress)

  • Wednesday, 5th August, 2026
  • 10:05am

A security flaw has been found in the Multi Uploader for Gravity Forms plugin for WordPress, affecting all versions up to and including 1.1.8. This issue lets people who do not have login access to your WordPress site permanently delete any media files you have uploaded to your site, such as product images, blog photos, videos, or documents.

The flaw occurs because the plugin does not properly verify user permissions for its file deletion feature, and exposes a security token on any public page that includes the plugin's multi-uploader form field. Attackers can use this exposed token, along with the ID of a media file in your library, to delete that file without your knowledge or permission.

In the worst case, bad actors could use this flaw to erase your entire WordPress media library. This would break any part of your website that relies on uploaded media, including product pages, blog posts, image galleries, and other content that uses images or files you have uploaded.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-5581

« Back