Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2026-87796 — Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab. | Kitploit
Инструменты/GitHubGitHub/abraxas/cve-2026-87796
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPapers & ResearchLearning & EducationPayload DevelopmentLabs & Practice
GitHubabraxas/cve-2026-87796

CVE-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab.

1257 дней назадЕщё не проверено
Репозиторий

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

Abraxas Labs - CVE-2026-87796

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-87796

CVE-2026-87796

Multi Uploader for Gravity Forms 1.1.9 - sh1zen

I am @abraxas_null. Loopback lab. The client is CVE-2026-87796-Abraxas-Labs.py.

The advisory named a method. move_file is a private PHP method, not HTTP action=. The ajax action is gfmu-plupload-submit. Chunked handleUpload (chunks>1) copies first, validates later. Non-chunked validates first. Directory listing is gone. No patch in the 1.1.9 tag I sat with. This is not Gravity Forms the commercial plugin.

CVECVE-2026-87796 · CVE.org
CWECWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductMulti Uploader for Gravity Forms
Affectedall versions through 1.1.9 (inclusive)
Patchedno public patch in 1.1.9 - remove the zip
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated multipart POST, two chunks, then GET the landed object from the plugin tmp dir. Arbitrary file write to a web-served path. That is RCE if the bytes are PHP. The lab writes a GIF89a plus a unique string, not a shell.


How I found it

Wordfence pointed at the lines. I read them in order. Function names in an advisory are PHP methods unless a hook says otherwise. action=move_file gets you the theme.

Nonce like a visitor (gfmu-upload-nonce). Field ids so chunking is on (currentFormID, currentFieldID, type multi-uploader). Empty settings means enable_chunked=false and you die on try activate chunking. Two POSTs, then a GET. {"success":true} then {"result":"success",...}. If you are still reading a DOCTYPE, you are still lost.

Wrong turns: admin-ajax body 0 (wrong action, or Gravity Forms never booted so the nopriv hook is missing); Server error. plus a nonce complaint; GET; an allowed jpg that lands (the product working).


The lab

Port 8088. gf-multi-uploader 1.1.9 plus Gravity Forms so the addon boots. Lab stub field with chunk_size. Discover nonce from slug gfmu-lab-nonce.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-87796-Abraxas-Labs.py

Witness: GET /wp-content/uploads/gfmu-uploads-tmp/poc_witness.php contains POC_WITNESS_87796 (GIF89a + echo).

Ways to lose without learning anything:

  • theme HTML / action=move_file
  • try activate chunking
  • Server error. nonce
  • allowed jpg only
  • reverse shell

The fix

There is no public patch in 1.1.9. Remove the zip. Re-run CVE-2026-87796-Abraxas-Labs.py after it is gone: the tmp file must not appear.


References

  • CVE-2026-87796 · NVD

  • CVE-2026-87796 · CVE.org

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/GFMUAddon.class.php#L125

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMUHandlePluploader.class.php#L257

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L319

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L322

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L560

  • www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017?source=cve

  • github.com/advisories/GHSA-h7vp-g8q2-89c8

  • nvd.nist.gov/vuln/detail/CVE-2026-87796

  • Plugin directory: gf-multi-uploader

  • Trac browser: plugins.trac.wordpress.org/gf-multi-uploader

  • SVN tags: plugins.svn.wordpress.org/gf-multi-uploader

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Скачать инструмент