Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-48866 — CVE-2026-48866 — Gravity Forms <= 2.10.0.1 경로 탐색을 통한 임의 파일 삭제 (CVSS 9.6) | Kitploit
도구/GitHubGitHub/0xabcd01/cve-2026-48866
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHub0xabcd01/cve-2026-48866

CVE-2026-48866

CVE-2026-48866 — Gravity Forms <= 2.10.0.1 경로 탐색을 통한 임의 파일 삭제 (CVSS 9.6)

저장소 보기
163개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2026-48866 CVSS 9.6 CWE-22 Affected Fixed

Type Access Trigger Platform Python License

---``` ┌───────────────────────────────────────────────────────────┐ │ │ │ C V E - 2 0 2 6 - 4 8 8 6 6 │ │ │ │ Gravity Forms Path Traversal → Arbitrary File Deletion │ │ │ └───────────────────────────────────────────────────────────┘

<h3 align="center">
  <code>gform_uploaded_files</code>가 URL에서 <code>../</code>를 허용합니다. 관리자의 삭제 클릭 시 임의 파일 삭제가 발생합니다.
</h3>

<p align="center">
  <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48866">NVD</a> •
  <a href="https://patchstack.com/database/wordpress/plugin/gravityforms/vulnerability/wordpress-gravity-forms-plugin-2-10-0-1-arbitrary-file-deletion-vulnerability">Patchstack</a> •
  <a href="https://github.com/codewurker/gravityforms/commit/cf2ff65133d581cfed1c308adc1621c3af1f8422">패치된 커밋</a> •
  <a href="https://github.com/codewurker/gravityforms">소스 미러</a>
</p>

---

## 목차

<table>
<tr>
<td width="50%">

**익스플로잇**
- [빠른 시작](#quick-start)
- [작동 방식](#how-it-works)
- [영향](#impact)
- [사용법](#usage)

</td>
<td width="50%">

**방어**
- [기술 심층 분석](#technical-deep-dive)
- [탐지](#detection)
- [수정](#remediation)
- [참고 자료](#references)

</td>
</tr>
</table>

---

## 빠른 시작```
┌─────────────────────────────────────────────────────────────────────┐
│  REQUIREMENTS                                                       │
│  ───────────────────────────────────────────────────────────────    │
│  Target    WordPress + Gravity Forms ≤ 2.10.0.1                     │
│  Form      Public form with a file upload field                     │
│  Python    3.8+ with requests                                       │
│  Auth      None (injection) / Admin creds (trigger)                 │
└─────────────────────────────────────────────────────────────────────┘

The script will automatically download the required model file and dependencies on first run.

  • Current support: Support session: YC / XY / UC / CD / JH / RG / YBI / YG / ZJ / QT / OT

키 기능

  • 간소화된 모드 관리: 터미널에서 몇 번의 클릭으로 세션을 빠르게 설정합니다.
  • 자동 데이터 관리: 충돌 해결 프롬프트와 함께 스마트한 로컬 및 원격 데이터 동기화.
  • 편리한 표시 이름 태깅: 빠른 식별을 위해 연락처에 쉽게 태그를 지정합니다.
  • 연락처 메시지 전송: 특정 연락처에 메시지를 보냅니다.
  • 그룹 메시지 전송: 특정 그룹에 메시지를 보냅니다.
  • 연락처 메시지 자동 응답: 특정 연락처의 메시지에 자동으로 응답합니다.
  • 그룹 메시지 자동 응답: 특정 그룹의 메시지에 자동으로 응답합니다.
  • 그룹 초대 자동 수락: 자동으로 그룹 초대를 수락하고 환영 메시지를 보냅니다.
  • 친구 요청 자동 수락: 자동으로 친구 요청을 수락합니다.
  • 예약된 그룹 메시지 전송: 특정 시간에 메시지를 보냅니다.
  • 예약된 연락처 메시지 전송: 특정 시간에 메시지를 보냅니다.```bash git clone https://github.com/0xABCD01/CVE-2026-48866.git cd CVE-2026-48866 pip install requests

Inject only (unauthenticated — file dies when admin cleans entries)

python3 poc.py -t https://test.com -f 1 -i 3

Full kill chain (admin creds provided — immediate deletion)

python3 poc.py -t https://test.com -f 1 -i 3 --trigger --admin-user admin --admin-pass 'P@ssw0rd'

---

## 작동 방식
도구 다운로드