CVE Database /
CVE-2026-48866
CVE · Critical
CVE-2026-48866 — Gravity Forms [gravityforms] < 2.10.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-48866
|
Gravity Forms [gravityforms] < 2.10.1 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Critical
9.6
|
< 2.10.1
|
2.10.1 |
2026-06-01 |
—
|
CVE-2026-48866
A critical vulnerability exists in Gravity Forms plugin versions prior to 2.10.0.1, allowing an unauthorized user to erase any file from the server by exploiting a flaw in path checking mechanisms. This oversight enables malicious actors to potentially execute arbitrary code on the affected system by deleting specific files, including sensitive configuration files like wp-config.php.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings