CVE · Critical

CVE-2026-48866 — Gravity Forms [gravityforms] < 2.10.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-48866 Gravity Forms [gravityforms] < 2.10.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.6 < 2.10.1 2.10.1 2026-06-01

CVE-2026-48866

A critical vulnerability exists in Gravity Forms plugin versions prior to 2.10.0.1, allowing an unauthorized user to erase any file from the server by exploiting a flaw in path checking mechanisms. This oversight enables malicious actors to potentially execute arbitrary code on the affected system by deleting specific files, including sensitive configuration files like wp-config.php.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.