Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-87796 — Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab. | Kitploit
Outils/GitHubGitHub/abraxas/cve-2026-87796
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPapers & ResearchLearning & EducationPayload DevelopmentLabs & Practice
GitHubabraxas/cve-2026-87796

CVE-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab.

125il y a 7 joursPas encore vérifié
Voir le dépôt

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

Abraxas Labs - CVE-2026-87796

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-87796

CVE-2026-87796

Multi Uploader for Gravity Forms 1.1.9 - sh1zen

I am @abraxas_null. Loopback lab. The client is CVE-2026-87796-Abraxas-Labs.py.

The advisory named a method. move_file is a private PHP method, not HTTP action=. The ajax action is gfmu-plupload-submit. Chunked handleUpload (chunks>1) copies first, validates later. Non-chunked validates first. Directory listing is gone. No patch in the 1.1.9 tag I sat with. This is not Gravity Forms the commercial plugin.

CVECVE-2026-87796 · CVE.org
CWECWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductMulti Uploader for Gravity Forms
Affectedall versions through 1.1.9 (inclusive)
Patchedno public patch in 1.1.9 - remove the zip
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated multipart POST, two chunks, then GET the landed object from the plugin tmp dir. Arbitrary file write to a web-served path. That is RCE if the bytes are PHP. The lab writes a GIF89a plus a unique string, not a shell.


How I found it

Wordfence pointed at the lines. I read them in order. Function names in an advisory are PHP methods unless a hook says otherwise. action=move_file gets you the theme.

Nonce like a visitor (gfmu-upload-nonce). Field ids so chunking is on (currentFormID, currentFieldID, type multi-uploader). Empty settings means enable_chunked=false and you die on try activate chunking. Two POSTs, then a GET. {"success":true} then {"result":"success",...}. If you are still reading a DOCTYPE, you are still lost.

Wrong turns: admin-ajax body 0 (wrong action, or Gravity Forms never booted so the nopriv hook is missing); Server error. plus a nonce complaint; GET; an allowed jpg that lands (the product working).


The lab

Port 8088. gf-multi-uploader 1.1.9 plus Gravity Forms so the addon boots. Lab stub field with chunk_size. Discover nonce from slug gfmu-lab-nonce.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-87796-Abraxas-Labs.py

Witness: GET /wp-content/uploads/gfmu-uploads-tmp/poc_witness.php contains POC_WITNESS_87796 (GIF89a + echo).

Ways to lose without learning anything:

  • theme HTML / action=move_file
  • try activate chunking
  • Server error. nonce
  • allowed jpg only
  • reverse shell

The fix

There is no public patch in 1.1.9. Remove the zip. Re-run CVE-2026-87796-Abraxas-Labs.py after it is gone: the tmp file must not appear.


References

  • CVE-2026-87796 · NVD

  • CVE-2026-87796 · CVE.org

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/GFMUAddon.class.php#L125

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMUHandlePluploader.class.php#L257

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L319

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L322

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L560

  • www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017?source=cve

  • github.com/advisories/GHSA-h7vp-g8q2-89c8

  • nvd.nist.gov/vuln/detail/CVE-2026-87796

  • Plugin directory: gf-multi-uploader

  • Trac browser: plugins.trac.wordpress.org/gf-multi-uploader

  • SVN tags: plugins.svn.wordpress.org/gf-multi-uploader

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Télécharger l’outil