Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-5581: Gravity Forms: Unauthorized Media Deletion in Multi Uploader
CVE-2026-5581
Summary
An attacker can delete any media file in your WordPress site without permission, potentially deleting all media files. This affects all versions of the Multi Uploader for Gravity Forms plugin up to and including 1.1.8. To protect your site, update to a newer version of the plugin.
Original title
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability check...
Original description
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce intended for CSRF protection is exposed on any public-facing page containing a multi-uploader form field via the `GFMU_options` JavaScript object. This makes it possible for unauthenticated attackers to permanently delete any WordPress media attachment by supplying its attachment ID, potentially leading to complete media library destruction.
nvd CVSS3.1
9.1
Vulnerability type
CWE-862
Missing Authorization
- https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/GFMUAddo...
- https://plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.8/inc/GFMU...
- https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/GFMUAddon.cla...
- https://plugins.trac.wordpress.org/browser/gf-multi-uploader/trunk/inc/GFMUHandl...
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new...
- https://www.wordfence.com/threat-intel/vulnerabilities/id/16dca898-1a98-4e0b-8f4...
Published: 5 Aug 2026 · Updated: 5 Aug 2026 · First seen: 5 Aug 2026