The email arrives on a Tuesday, forwarded by whoever on your staff subscribes to security mailing lists. A vulnerability in Gravity Forms. High severity. Unauthenticated. More than a million sites. You scroll to the bottom looking for the sentence that tells you what to do, and what you find is an offer: if you need your site cleaned immediately, there is a product for that, available around the clock, with a one-hour response time.
That is a real service, and there are days when it is the only thing that helps. It is also the most expensive sentence in the email, and by the time it applies to you, every decision that mattered was made weeks earlier.
Where this comes from. The vulnerability details below come from Wordfence’s own entry in its vulnerability database and from the Gravity Forms changelog, both of which we checked directly. The disclosure timeline comes from Wordfence’s advisory email. We have kept those separate, and we have flagged the one place where the framing and the facts point in different directions.
What Was Actually Found
Wordfence Argus, the automated research system built by the Wordfence Threat Intelligence team, found an arbitrary file upload vulnerability in Gravity Forms. It is tracked as CVE-2026-19513, classified as unrestricted upload of file with dangerous type, and scored 8.1, which puts it in the high band rather than the critical one. It affects all versions up to and including 3.0.2, and it is fixed in 3.0.3. Wordfence credits Alex Thomas along with Argus, and published the entry on September 1, 2026.
One detail in the score changes how urgent this is. The published vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Most of that reads the way you would expect for something worth an email: reachable over the network, no privileges required, no user interaction. The middle term is the one worth pausing on. AC:H means attack complexity high. The name Wordfence gave the flaw, state/chunk hash confusion, describes a condition an attacker has to engineer rather than one they trip over.
That is not permission to relax. In the twenty-four hours after the entry went public, Wordfence’s own page reported six blocked attempts against it. High complexity slows down opportunistic mass scanning. It does nothing about somebody who has decided to spend an afternoon on your organization specifically.
The Timeline, and the Gap in the Middle
The dates here matter more than the severity, because the interesting question this disclosure raises is not how bad the flaw is. It is who was protected when.
- August 9, 2026 — Wordfence Argus discovers the vulnerability.
- August 11, 2026 — Wordfence discloses it to Gravity Forms through its vulnerability management portal.
- August 13, 2026 — Wordfence Premium, Care and Response customers receive a firewall rule.
- August 20, 2026 — Gravity Forms acknowledges the report and ships 3.0.3 the same day.
- September 1, 2026 — The vulnerability is published in full, with technical detail, in the public database.
- September 12, 2026 — Free Wordfence users receive the same firewall rule, thirty days behind the paid tiers.
Read the last two lines together and the shape is uncomfortable. The full description became public on September 1. Sites relying on the free tier of the firewall are covered on September 12. That is an eleven-day stretch in which the details are available to anyone who wants them and the network-level protection is not.
Now the correction, because the timeline is misleading on its own. The gap only exists for sites that have not updated. The patch has been available since August 20, and it closes the hole regardless of which firewall tier you are on, or whether you run a firewall at all. This is worth saying plainly, because the shape of that timeline invites exactly the wrong conclusion. A firewall rule is a mitigation for sites running vulnerable code. Updating is the fix. If your install is on 3.0.3 or newer, September 12 is a date you can ignore entirely.
Which Version You Actually Want
3.0.3 is the minimum, not the target. Gravity Forms shipped 3.1.0 on August 25 and has released further patch versions on that branch since. Advisories name the first version that carries the fix, which is the right thing for an advisory to do and the wrong thing to type into a maintenance ticket. If you are opening the plugins screen anyway, go to the current 3.1 release rather than to the specific number in the bulletin.
The Part That Catches Associations
Gravity Forms is a commercial plugin. It is not distributed through the WordPress.org repository, and that has two consequences a free-plugin advisory would never carry.
The first is that the install figure is an estimate. Wordfence describes the plugin as having more than a million active installations, and that number has been repeated everywhere this week. There is no public install counter for a commercial plugin the way there is for a repository one, so there is nothing to check it against. It is a reasonable estimate from people with good visibility, and we are repeating it as an estimate rather than as a measurement.
The second one is the one that will actually bite somebody this month. Updates for Gravity Forms are gated behind an active license key, and the vendor is unusually clear about what expiry costs. Its own documentation states that when a license lapses, the plugin and its add-ons “will remain on your site(s) and continue to operate,” and that you will “no longer be able to receive application updates (including bug fixes and security updates).”
Nothing breaks. That is the whole problem. An association whose Gravity Forms license quietly lapsed in March has working forms, a functioning event registration page, a donation form that still takes money, no error a communications coordinator would read as urgent, and no route to 3.0.3. The site looks exactly like a healthy site. It is running code with a published vulnerability and no mechanism to leave it.
The ways a license lapses are depressingly ordinary. It was bought by a developer who has since moved on and billed to their card. It sits in an agency account under a relationship that ended two years ago. It renewed annually against a card that expired, and the failure notice went to an inbox nobody monitors. In every one of those cases the forms kept working, which is precisely why nobody looked.
What to Do This Week
None of this takes long, and the order matters, because the first item tells you whether the rest are urgent.
- Check the installed version first. Plugins screen, or wp plugin get gravityforms –field=version from the command line. Anything at 3.0.2 or below is exposed and should be treated as the priority for the day.
- Check the license status before you try to update. If it has expired, the update button will not save you, and finding that out during the update is worse than finding it out now. Renewing may take a purchasing conversation, which is a slower process than a plugin update and needs to start today rather than after the weekend.
- Update, on a staging copy if you have one. Take the current 3.1 release rather than 3.0.3 specifically, and take the add-ons with it. Test the forms that take money afterward, not before.
- If you were on a vulnerable version and the site is public, look before you assume. Look for files in the uploads directory that you cannot account for, particularly recent ones with executable extensions, and for administrator accounts nobody recognizes. If you find either, stop and get incident response involved rather than deleting things, because deleting the evidence makes the next hour harder.
- Then widen the question. Every commercial plugin and premium theme on the site has the same license-gated update path and the same silent failure mode. Gravity Forms is the one with an advisory this week. It is very unlikely to be the only lapsed license on the server.
What the Advisory Gets Right, and What It Leaves Out
The Wordfence advisory is accurate, it is timely, and the research behind it is the reason anybody knew about this in August rather than in November. The closing offer is honest about what it is, too: incident response, for organizations that have already been compromised, at the point where speed is genuinely worth paying for.
What it does not say, because it is not their job to say it, is that almost nobody who reads that sentence needed to arrive there. The distance between this advisory and a cleanup invoice is a version number and a license renewal. Both of those are calendar work. Neither is interesting, neither generates an email, and neither will ever feel like the most important thing on a Tuesday.
That is the real lesson in the thirty-day gap between the paid firewall rule and the free one. It is not an argument for buying a particular firewall tier. It is a reminder that every layer in front of your site is compensating for code you have not updated yet, and that the layer doing the most work is the one nobody sees: somebody who knows what is installed, knows which licenses are current, and reads the advisories in the week they land rather than the month after.
Find Out Where You Actually Stand
Send us your site, or just a list of what is installed on it. We will come back in writing with which of your plugins and themes are commercial, which of those have licenses that have lapsed or expire inside ninety days, which are running versions with published vulnerabilities, and which of your forms accept file uploads from people who are not logged in. Every item comes back with the version you are on and the version you should be on next to it, separated into what we can fix and what needs a purchasing decision on your end. If everything is current, we will tell you that, and it costs you nothing to hear it.