VYPR

Piotnet Forms

by WordPress

CVEs (1)

  • CVE-2026-4883CriMay 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks…