plugin

Pie Forms For Wp Vulnerabilities

6 known security issues reported for the Pie Forms For Wp WordPress plugin. Most recent disclosed Nov 18, 2025.

1 high 2 medium

Running Pie Forms For Wp on your site? Check whether your installed version is affected.

Scan your site free

Pie Forms — Drag &amp; Drop Form Builder [pie-forms-for-wp] <= 1.6 (unfixed)

unknown

[en] The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic function. This is due to insufficient file type validation where the validate_classic method validates file extensions and sets error messages but does not prevent the f...

Affected:
up to 1.6
Fix:
No patched version reported
Disclosed:
Nov 18, 2025

CVE-2025-12528 on NVD →

Pie Forms for WP <= 1.6 - Unauthenticated Arbitrary File Upload

high

The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6 via the format_classic function. This is due to insufficient file type validation where the validate_classic method validates file extensions and sets error messages but does not prevent the file u...

CVSS:
8.1
Affected:
up to 1.6
Fix:
No patched version reported
Disclosed:
Nov 17, 2025

CVE-2025-12528 on NVD →

Pie Forms — Drag &amp; Drop Form Builder [pie-forms-for-wp] < 1.5

unknown

[en] The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping....

Affected:
up to 1.5
Fixed in:
1.5
Disclosed:
Dec 7, 2024

CVE-2024-11436 on NVD →

Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! <= 1.4.19 - Reflected Cross-Site Scripting

medium

The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.4.19 due to insufficient input sanitization and output escaping. This...

CVSS:
6.1
Affected:
up to 1.4.19
Fixed in:
1.5
Disclosed:
Dec 6, 2024

CVE-2024-11436 on NVD →

Pie Forms — Drag &amp; Drop Form Builder [pie-forms-for-wp] < 1.4.9.4

unknown

[en] The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_htm...

Affected:
up to 1.4.9.4
Fixed in:
1.4.9.4
Disclosed:
Jun 6, 2022

CVE-2022-1569 on NVD →

WordPress Forms by Pie Forms <= 1.4.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is...

CVSS:
5.5
Affected:
up to 1.4.9.4
Fixed in:
1.4.9.4
Disclosed:
May 12, 2022

CVE-2022-1569 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database