CVE-2026-84434 affects Gravity Forms, a widely used WordPress form-building plugin, in all versions up to and including 3.1.0.4. NVD classifies it as CWE-434 (Unrestricted Upload of File with Dangerous Type). Our source data does not carry a CVSS score for this CVE as of our ingestion — NVD has not yet published one. VulnCheck’s KEV feed reports the CVE as exploited, dated September 18, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-84434 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
Per NVD, the vulnerability stems from a mismatch between the plugin’s field-validation pipeline and its file-persistence pipeline. A File Upload field configured with its visibility set to “Hidden” bypasses the plugin’s extension-validation check, and a file that pipeline rejects can still have its intact upload state passed to the plugin’s file-persistence function without being re-validated. NVD states this makes it possible for an unauthenticated attacker to upload a potentially executable file, opening a path to remote code execution.
Exploitation requires the targeted form to actually contain a File Upload field configured with Hidden visibility — a specific but, per NVD’s own description, reachable configuration on any publicly accessible Gravity Forms form that uses it.
Evidence and confidence
- Medium confidence — the CWE-434 classification and the described mechanism trace to NVD alone in our current ingestion, corroborated by a Wordfence Threat Intelligence advisory. The exploitation report traces to VulnCheck KEV alone.
- Our source data does not carry a CVSS score, vector, or EPSS score/percentile for this CVE.
No field is in conflict between our two sources. Our source data does not carry a specific fixed-version number.
Why this matters
Gravity Forms is one of the most widely deployed WordPress form plugins, and a bypass that lets an unauthenticated attacker upload a potentially executable file is functionally a remote-code-execution primitive, regardless of the missing CVSS score. Any site using a File Upload field with Hidden visibility on a publicly reachable form should treat this as an urgent patch, independent of severity scoring that hasn’t yet been published.
Frequently Asked Questions
What is CVE-2026-84434? An unauthenticated arbitrary file upload vulnerability (CWE-434) in the Gravity Forms WordPress plugin, affecting versions up to and including 3.1.0.4, reachable when a form contains a File Upload field configured with Hidden visibility.
Is CVE-2026-84434 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 18, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this? No. NVD’s description confirms this is exploitable by an unauthenticated attacker, provided the target form has a Hidden-visibility File Upload field.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number. Consult Gravity Forms’ own changelog for the current patched release.
Weakness classification and the described mechanism sourced from the National Vulnerability Database record for CVE-2026-84434, corroborated by Wordfence’s Threat Intelligence advisory. Exploitation status and the September 18, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. No CVSS score or EPSS data was available in our ingestion as of this writing. Aggregated September 20, 2026. See more vulnerability intelligence.