Pie Forms — Drag & Drop Form Builder [pie-forms-for-wp] <= 1.6 (unfixed)
unknown
[en] The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic function. This is due to insufficient file type validation where the validate_classic method validates file extensions and sets error messages but does not prevent the f...
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 18, 2025
CVE-2025-12528 on NVD →
Pie Forms for WP <= 1.6 - Unauthenticated Arbitrary File Upload
high
The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic function. This is due to insufficient file type validation where the validate_classic method validates file extensions and sets error messages but does not prevent the file u...
- CVSS:
- 8.1
- Affected:
- up to 1.6
- Fix:
- No patched version reported
- Disclosed:
- Nov 17, 2025
CVE-2025-12528 on NVD →
Pie Forms — Drag & Drop Form Builder [pie-forms-for-wp] < 1.5
unknown
[en] The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping....
- Affected:
- up to 1.5
- Fixed in:
- 1.5
- Disclosed:
- Dec 7, 2024
CVE-2024-11436 on NVD →
Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! <= 1.4.19 - Reflected Cross-Site Scripting
medium
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping. This...
- CVSS:
- 6.1
- Affected:
- up to 1.4.19
- Fixed in:
- 1.5
- Disclosed:
- Dec 6, 2024
CVE-2024-11436 on NVD →
Pie Forms — Drag & Drop Form Builder [pie-forms-for-wp] < 1.4.9.4
unknown
[en] The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_htm...
- Affected:
- up to 1.4.9.4
- Fixed in:
- 1.4.9.4
- Disclosed:
- Jun 6, 2022
CVE-2022-1569 on NVD →
WordPress Forms by Pie Forms <= 1.4.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is...
- CVSS:
- 5.5
- Affected:
- up to 1.4.9.4
- Fixed in:
- 1.4.9.4
- Disclosed:
- May 12, 2022
CVE-2022-1569 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database