CVE-2025-13407PoC

LOWCVSS 6.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Gravity Forms WordPress plugin before 2.9.23.1 does not properly prevent users from uploading dangerous files through its chunked upload functionality, allowing attackers to upload PHP files to affected sites and achieve Remote Code Execution, granted they can discover or enumerate the upload path.

3.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-26: 1Exploit Tool / Code · 2026-06-26: 1Technical Details · 2026-06-26: 106-26
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2025-13407-gravityforms-version-2-9-23-0-critical-vulnerability-proof-of-concept CVE-2025-13407 gravityforms (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomice…

    Post summary

    The post advertises a proof‑of‑concept for CVE‑2025‑13407, a critical GravityForms vulnerability with a CVSS of 9.8, without indicating ongoing exploitation or available mitigations.

    0000048
    11 followersView on X

Explore more