
Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab.
abraxaslabs.tech · github.com/abraxas · @abraxas_null · [email protected] · CVE-2026-87796
Multi Uploader for Gravity Forms 1.1.9 - sh1zen
I am @abraxas_null. Loopback lab. The client is CVE-2026-87796-Abraxas-Labs.py.
The advisory named a method. move_file is a private PHP method, not HTTP action=. The ajax action is gfmu-plupload-submit. Chunked handleUpload (chunks>1) copies first, validates later. Non-chunked validates first. Directory listing is gone. No patch in the 1.1.9 tag I sat with. This is not Gravity Forms the commercial plugin.
| CVE | CVE-2026-87796 · CVE.org |
| CWE | CWE-434 |
| CVSS | Critical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Product | Multi Uploader for Gravity Forms |
| Affected | all versions through 1.1.9 (inclusive) |
| Patched | no public patch in 1.1.9 - remove the zip |
| Auth | none |
| License | GNU Affero GPL v3.0 |
| Lab | 127.0.0.1 only |
Unauthenticated multipart POST, two chunks, then GET the landed object from the plugin tmp dir. Arbitrary file write to a web-served path. That is RCE if the bytes are PHP. The lab writes a GIF89a plus a unique string, not a shell.
Wordfence pointed at the lines. I read them in order. Function names in an advisory are PHP methods unless a hook says otherwise. action=move_file gets you the theme.
Nonce like a visitor (gfmu-upload-nonce). Field ids so chunking is on (currentFormID, currentFieldID, type multi-uploader). Empty settings means enable_chunked=false and you die on try activate chunking. Two POSTs, then a GET. {"success":true} then {"result":"success",...}. If you are still reading a DOCTYPE, you are still lost.
Wrong turns: admin-ajax body 0 (wrong action, or Gravity Forms never booted so the nopriv hook is missing); Server error. plus a nonce complaint; GET; an allowed jpg that lands (the product working).
Port 8088. gf-multi-uploader 1.1.9 plus Gravity Forms so the addon boots. Lab stub field with chunk_size. Discover nonce from slug gfmu-lab-nonce.
Target only 127.0.0.1:8088 (or the loopback you bound).
cd lab
docker compose up --force-recreate
python3 ../CVE-2026-87796-Abraxas-Labs.py
Witness: GET /wp-content/uploads/gfmu-uploads-tmp/poc_witness.php contains POC_WITNESS_87796 (GIF89a + echo).
Ways to lose without learning anything:
action=move_filetry activate chunkingServer error. nonceThere is no public patch in 1.1.9. Remove the zip. Re-run CVE-2026-87796-Abraxas-Labs.py after it is gone: the tmp file must not appear.
plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/GFMUAddon.class.php#L125
plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L319
plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L322
plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L560
www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017?source=cve
Plugin directory: gf-multi-uploader
Trac browser: plugins.trac.wordpress.org/gf-multi-uploader
Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null
GNU Affero GPL v3.0. See LICENSE.
The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.