The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS). | |
| Title | Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-11T06:00:19.467Z
Reserved: 2026-09-22T18:57:53.912Z
Link: CVE-2026-96227
No data.
Status : Received
Published: 2026-10-11T07:17:29.543
Modified: 2026-10-11T07:17:29.543
Link: CVE-2026-96227
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.