Get concise advice on choosing the right CMS, understanding migration costs, and avoiding expensive implementation mistakes before they become roadmap problems.
Your company's WordPress website could be exposed. Check this plugin today.
A critical vulnerability has been disclosed in Gravity Forms, a widely used WordPress form plugin.
CVE-2026-84434 carries a severity score of 9.8 out of 10.
The vulnerability could allow attackers to upload potentially executable files without logging in, potentially leading to remote code execution.
Not every Gravity Forms installation is exploitable. The attack requires a publicly accessible form containing a File Upload field with its visibility set to Hidden.
If your company runs its website on WordPress, here's what to do today:
Ask whoever manages your website whether Gravity Forms is installed.
If it is, check that you're running version 3.1.1 or newer. Version 3.1.2 is also available.
Ask them to review your forms for hidden file upload fields and investigate suspicious uploads if your site was exposed.
Make sure your contact forms, lead generation forms, and integrations still work after updating.
The security fix was released on September 3. The vulnerability was publicly disclosed on September 18.
For more than two weeks, the fix was available, but the release notes described it only as "security enhancements."
Why dependency control matters
Every third-party plugin introduces another dependency that needs to be monitored, updated, and tested.
This is one of the primary reasons I build client websites with Payload CMS. We can implement form handling, uploads, and integrations directly in the application layer rather than relying on an ever-growing collection of third-party plugins.