cvemon logocvemon logo

Activity

Trending

CVEs

CVE-2025-23921

Published Jan 22, 2025

Last updated 6 days ago

  1. Overview

  2. Weaknesses

  3. Social media

  4. References

Overview

Description
Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3.
Source
audit@patchstack.com
NVD status
Awaiting Analysis

Weaknesses

audit@patchstack.com
CWE-434

Social media

Hype score
Not currently trending
  1. CVE-2025-23921 Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Multi Uploader for Gravity Forms allows Upload a Web Shell to a Web Server. This issue affec… https://t.co/ugYGmVSM48

    @CVEnew

    22 Jan 2025

    174 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [CVE-2025-23921: CRITICAL] "Unrestricted file upload vulnerability in NotFound Multi Uploader for Gravity Forms enables attackers to upload web shells to servers. Multi Uploader versions up to 1.1.3 affected."#cybersecurity,#vulnerability https://t.co/kkApWmxKqU https://t.co/u0UO

    @CveFindCom

    22 Jan 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-23921
  • https://patchstack.com/database/Wordpress/Plugin/gf-multi-uploader/vulnerability/wordpress-multi-uploader-for-gravity-forms-plugin-1-1-3-arbitrary-file-upload-vulnerability?_s_id=cve
TRY INTRUDER
Intruder logo

© 2026 Intruder Systems Ltd.

AboutPrivacySitemapFeeds