Input validation vulnerability in Piotnet Forms 1.0.26

The Piotnet Forms plugin for WordPress has a security vulnerability that affects versions up to and including 1.0.26. An unauthenticated attacker can upload any type of file to the website’s server, which could allow them to execute code remotely. This is due to an issue with the ‘piotnetforms_ajax_form_builder’ function, which does not validate what type of file is being uploaded.

Detected in:

Piotnet Forms open vulnerable versions: >= * <= 1.0.28

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.