Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-48866 — WordPress Gravity Forms Plugin File Upload Path Traversal Arbitrary File Deletion

Summary

CVE-2026-48866: unauthenticated attackers can poison Gravity Forms entries with ../ sequences that delete arbitrary server files, including wp-config.php, when an admin removes the entry.
CVE
CVE-2026-48866
Published
Collected

original ↗