The disclosure timeline for the unauthenticated Arbitrary File Upload vulnerability in Gravity Forms is as follows:
-
August 9, 2026: Wordfence discovered the vulnerability during internal research using their security tool, Argus.
-
August 11, 2026: The team validated the findings and officially disclosed the issue to the vendor (Gravity Forms).
This timeline highlights that it took just two days from discovery to validation and disclosure. This rapid response is typical of professional security teams who aim to ensure vendors have sufficient time to address the vulnerability while minimizing potential harm.
The Gravity Forms team responded by releasing a patch in version 3.0.3, which was made available on August 20, 2026. The Wordfence blog post also includes details about how their firewall can block exploitation attempts, providing an additional layer of security for users who may not have updated immediately.
Key Points from the Patch
- Random Temporary Basenames: Server-generated random basenames are used to prevent attackers from controlling file names.
- Signed State Validation: Each chunk upload is validated against a signed state token that includes server-generated data and prevents unauthorized continuation of uploads.
- File Extension Checks:
Read the full article at Wordfence
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.



