Impact
This vulnerability is a Path Traversal flaw within the Gravity Forms plugin, allowing an attacker to craft a request that causes the server to delete arbitrary files, potentially removing essential configuration or application files.
Affected Systems
The flaw affects all installations of the WordPress Gravity Forms plugin with a version of 2.10.0.1 or earlier, released by Rocketgenius Inc.
Risk and Exploitability
The CVSS score of 9.6 signals a critical severity. EPSS information is not available, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves submitting a specially crafted request through the plugin’s form configuration or administrative interface, though the exact method is not explicitly stated in the description.
OpenCVE Enrichment