Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-87796 — Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab. | Kitploit
Herramientas/GitHubGitHub/abraxas/cve-2026-87796
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPapers & ResearchLearning & EducationPayload DevelopmentLabs & Practice
GitHubabraxas/cve-2026-87796

CVE-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab.

125hace 7 díasAún no revisado
Ver Repositorio

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

Abraxas Labs - CVE-2026-87796

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-87796

CVE-2026-87796

Multi Uploader for Gravity Forms 1.1.9 - sh1zen

I am @abraxas_null. Loopback lab. The client is CVE-2026-87796-Abraxas-Labs.py.

The advisory named a method. move_file is a private PHP method, not HTTP action=. The ajax action is gfmu-plupload-submit. Chunked handleUpload (chunks>1) copies first, validates later. Non-chunked validates first. Directory listing is gone. No patch in the 1.1.9 tag I sat with. This is not Gravity Forms the commercial plugin.

CVECVE-2026-87796 · CVE.org
CWECWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductMulti Uploader for Gravity Forms
Affectedall versions through 1.1.9 (inclusive)
Patchedno public patch in 1.1.9 - remove the zip
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated multipart POST, two chunks, then GET the landed object from the plugin tmp dir. Arbitrary file write to a web-served path. That is RCE if the bytes are PHP. The lab writes a GIF89a plus a unique string, not a shell.


How I found it

Wordfence pointed at the lines. I read them in order. Function names in an advisory are PHP methods unless a hook says otherwise. action=move_file gets you the theme.

Nonce like a visitor (gfmu-upload-nonce). Field ids so chunking is on (currentFormID, currentFieldID, type multi-uploader). Empty settings means enable_chunked=false and you die on try activate chunking. Two POSTs, then a GET. {"success":true} then {"result":"success",...}. If you are still reading a DOCTYPE, you are still lost.

Wrong turns: admin-ajax body 0 (wrong action, or Gravity Forms never booted so the nopriv hook is missing); Server error. plus a nonce complaint; GET; an allowed jpg that lands (the product working).


The lab

Port 8088. gf-multi-uploader 1.1.9 plus Gravity Forms so the addon boots. Lab stub field with chunk_size. Discover nonce from slug gfmu-lab-nonce.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-87796-Abraxas-Labs.py

Witness: GET /wp-content/uploads/gfmu-uploads-tmp/poc_witness.php contains POC_WITNESS_87796 (GIF89a + echo).

Ways to lose without learning anything:

  • theme HTML / action=move_file
  • try activate chunking
  • Server error. nonce
  • allowed jpg only
  • reverse shell

The fix

There is no public patch in 1.1.9. Remove the zip. Re-run CVE-2026-87796-Abraxas-Labs.py after it is gone: the tmp file must not appear.


References

  • CVE-2026-87796 · NVD

  • CVE-2026-87796 · CVE.org

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/GFMUAddon.class.php#L125

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMUHandlePluploader.class.php#L257

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L319

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L322

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L560

  • www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017?source=cve

  • github.com/advisories/GHSA-h7vp-g8q2-89c8

  • nvd.nist.gov/vuln/detail/CVE-2026-87796

  • Plugin directory: gf-multi-uploader

  • Trac browser: plugins.trac.wordpress.org/gf-multi-uploader

  • SVN tags: plugins.svn.wordpress.org/gf-multi-uploader

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Descargar herramienta