CVE-2026-48866 — WordPress Gravity Forms Plugin File Upload Path Traversal Arbitrary File Deletion
aretiq.ai | research | CVE-2026-48866 | #vulnerability-research | #web-security | #wordpress | #path-traversal | #cve-2026-48866 | #gravity-forms | #arbitrary-file-deletion
Summary
CVE-2026-48866: unauthenticated attackers can poison Gravity Forms entries with ../ sequences that delete arbitrary server files, including wp-config.php, when an admin removes the entry.
- CVE
- CVE-2026-48866
- Published
- Collected
Skip to content