Description
The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).
Published:
2026-10-11
Score:
n/a
EPSS:
n/a
KEV:
No
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sun, 11 Oct 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS). | |
| Title | Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-11T06:00:19.467Z
Reserved: 2026-09-22T18:57:53.912Z
Link: CVE-2026-96227
No data.
Status : Received
Published: 2026-10-11T07:17:29.543
Modified: 2026-10-11T07:17:29.543
Link: CVE-2026-96227
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.