1.
aretiq.ai | research | | original ↗ | #vulnerability-research | #web-security | #wordpress | #path-traversal
CVE-2026-48866: unauthenticated attackers can poison Gravity Forms entries with ../ sequences that delete arbitrary server files, including wp-config.php, when an admin removes the entry.
Skip to content