CVE-2026-48866: WordPress Gravity Forms plugin <= 2.10.0.1 - Arbitrary File Deletion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal.
This issue affects Gravity Forms: from n/a through 2.10.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Gravity Forms pluginto a version that resolves this vulnerability.Fixed in 2.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48866?
The severity of CVE-2026-48866 is rated as critical with a score of 9.6.
How do I fix CVE-2026-48866?
To fix CVE-2026-48866, update the WordPress Gravity Forms plugin to the latest version, at least 2.10.1.
What type of vulnerability is CVE-2026-48866?
CVE-2026-48866 is a Path Traversal vulnerability that allows arbitrary file deletion.
Which versions of Gravity Forms are affected by CVE-2026-48866?
CVE-2026-48866 affects Gravity Forms versions from n/a up to and including 2.10.0.1.
What are the potential impacts of CVE-2026-48866?
The impacts of CVE-2026-48866 include the potential for unauthorized file deletion, which can compromise the integrity of affected systems.