CVE-2026-5581 (matched: wordpress)

  • Wednesday, 5th August, 2026
  • 16:05pm

A security flaw has been identified in the WordPress plugin Multi Uploader for Gravity Forms, which is used to add multi-file upload functionality to Gravity Forms on your site. This vulnerability affects all versions of the plugin up to and including version 1.1.8.

The issue allows unauthenticated attackers (people who do not have login access to your WordPress admin area) to permanently delete any media stored in your site’s media library, including images, videos, and documents. By supplying the ID of a media file, an attacker can erase it for good, and could potentially wipe your entire media library with no way to recover lost content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-5581

« Back