Junglewise Threat Intelligence

CVE-2026-48866: Rocketgenius Gravity Forms path traversal leading to file deletion

CVE-2026-48866 · Severity: critical · CVSS 9.6 · Published 2026-06-01

Technologies: Rocketgenius Gravity Forms. Vendors: Rocketgenius.

Executive brief

Gravity Forms is a popular WordPress plugin used to create and manage web forms. A security flaw in this plugin allows an attacker to delete critical files from the website's server. This could lead to a complete site failure, loss of data, or the removal of security configurations, potentially allowing further compromise of the web server.

Technical details

A path traversal vulnerability (CWE-22) exists in the Gravity Forms plugin for WordPress. The flaw allows unauthenticated attackers to delete arbitrary files on the server by manipulating file paths, though exploitation requires a privileged user to interact with a malicious link or crafted page (User Interaction: Required). Successful exploitation can result in the deletion of critical system or application files, leading to a denial of service or security bypass. The issue is fixed in version 2.10.1.

Affected products

  • Rocketgenius Inc. Gravity Forms up to 2.10.0.1

Timeline

  • 2026-04-29: other: Reported by researcher daroo
  • 2026-06-01: advisory: Published by Patchstack and NVD
  • 2026-06-01: patched: Version 2.10.1 released

References

Related threats