Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-87796 — Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab. | Kitploit
工具/GitHubGitHub/abraxas/cve-2026-87796
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingPapers & ResearchLearning & EducationPayload DevelopmentLabs & Practice
GitHubabraxas/cve-2026-87796

CVE-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with a loopback Docker lab.

1257天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
查看仓库
分享
内容在请求的语言中不可用。显示英文版本。

Abraxas Labs - CVE-2026-87796

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-87796

CVE-2026-87796

Multi Uploader for Gravity Forms 1.1.9 - sh1zen

I am @abraxas_null. Loopback lab. The client is CVE-2026-87796-Abraxas-Labs.py.

The advisory named a method. move_file is a private PHP method, not HTTP action=. The ajax action is gfmu-plupload-submit. Chunked handleUpload (chunks>1) copies first, validates later. Non-chunked validates first. Directory listing is gone. No patch in the 1.1.9 tag I sat with. This is not Gravity Forms the commercial plugin.

CVECVE-2026-87796 · CVE.org
CWECWE-434
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductMulti Uploader for Gravity Forms
Affectedall versions through 1.1.9 (inclusive)
Patchedno public patch in 1.1.9 - remove the zip
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Unauthenticated multipart POST, two chunks, then GET the landed object from the plugin tmp dir. Arbitrary file write to a web-served path. That is RCE if the bytes are PHP. The lab writes a GIF89a plus a unique string, not a shell.


How I found it

Wordfence pointed at the lines. I read them in order. Function names in an advisory are PHP methods unless a hook says otherwise. action=move_file gets you the theme.

Nonce like a visitor (gfmu-upload-nonce). Field ids so chunking is on (currentFormID, currentFieldID, type multi-uploader). Empty settings means enable_chunked=false and you die on try activate chunking. Two POSTs, then a GET. {"success":true} then {"result":"success",...}. If you are still reading a DOCTYPE, you are still lost.

Wrong turns: admin-ajax body 0 (wrong action, or Gravity Forms never booted so the nopriv hook is missing); Server error. plus a nonce complaint; GET; an allowed jpg that lands (the product working).


The lab

Port 8088. gf-multi-uploader 1.1.9 plus Gravity Forms so the addon boots. Lab stub field with chunk_size. Discover nonce from slug gfmu-lab-nonce.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-87796-Abraxas-Labs.py

Witness: GET /wp-content/uploads/gfmu-uploads-tmp/poc_witness.php contains POC_WITNESS_87796 (GIF89a + echo).

Ways to lose without learning anything:

  • theme HTML / action=move_file
  • try activate chunking
  • Server error. nonce
  • allowed jpg only
  • reverse shell

The fix

There is no public patch in 1.1.9. Remove the zip. Re-run CVE-2026-87796-Abraxas-Labs.py after it is gone: the tmp file must not appear.


References

  • CVE-2026-87796 · NVD

  • CVE-2026-87796 · CVE.org

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/GFMUAddon.class.php#L125

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMUHandlePluploader.class.php#L257

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L319

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L322

  • plugins.trac.wordpress.org/browser/gf-multi-uploader/tags/1.1.9/inc/GFMU_FileUploader.php#L560

  • www.wordfence.com/threat-intel/vulnerabilities/id/47337bc1-fa3d-470c-9524-859295261017?source=cve

  • github.com/advisories/GHSA-h7vp-g8q2-89c8

  • nvd.nist.gov/vuln/detail/CVE-2026-87796

  • Plugin directory: gf-multi-uploader

  • Trac browser: plugins.trac.wordpress.org/gf-multi-uploader

  • SVN tags: plugins.svn.wordpress.org/gf-multi-uploader

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

下载工具