CVE-2025-23921: SH1ZEN Multi Uploader For Gravity Forms

Critical severity, CVSS 9.0. EPSS: 0.5% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in sh1zen Multi Uploader for Gravity Forms gf-multi-uploader allows Upload a Web Shell to a Web Server.This issue affects Multi Uploader for Gravity Forms: from n/a through <= 1.1.3.

Affected products

  • SH1ZEN Multi Uploader For Gravity Forms: up to and including 1.1.3

Published 2025-01-22. Last modified 2026-06-17.