CVE detail
CVE-2014-4972 — CVE-2014-4972
Published 2018-01-08 · Modified 2026-06-17 · Vendor ajax_upload_for_gravity_forms_project · Product ajax_upload_for_gravity_forms · Source nvd
CRITICAL
severity
CVSS-derived band
0.0465
EPSS probability
exploitation probability, 30d
91.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References