CVE-2026-19513: Gravity Forms unauthenticated file upload risk and what site owners should do

Originally published at: CVE-2026-19513: Gravity Forms unauthenticated file upload risk and what site owners should do - ToolsLib Blog

CVE-2026-19513 affects Gravity Forms ≤ 3.0.2, allowing unauthenticated file writes under specific conditions. Update to 3.0.3+ and verify upload directory behavior, especially on NGINX.