plugin

Piotnetforms Vulnerabilities

14 known security issues reported for the Piotnetforms WordPress plugin. Most recent disclosed Sep 22, 2025.

1 critical 1 high 4 medium 1 low

Running Piotnetforms on your site? Check whether your installed version is affected.

Scan your site free

Piotnet Forms <= 1.0.30 - Cross-Site Request Forgery

medium

The Piotnet Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.30. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tr...

CVSS:
4.3
Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Sep 22, 2025

CVE-2025-57933 on NVD →

Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms. This issue affects Piotnet Forms: from n/a through 1.0.30.

Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2025-32205 on NVD →

Piotnet Forms <= 1.0.30 - Authenticated (Editor+) Path Traversal

low

The Piotnet Forms plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.30. This makes it possible for authenticated attackers, with Editor-level access and above, to perform actions on files outside of the originally intended directory.

CVSS:
3.8
Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Apr 7, 2025

CVE-2025-32205 on NVD →

Piotnet Forms <= 1.0.30 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Piotnet Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that w...

CVSS:
6.4
Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31792 on NVD →

Piotnet Forms <= 1.0.30 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Piotnet Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.0.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web s...

CVSS:
4.4
Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31793 on NVD →

Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.

Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31792 on NVD →

Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.

Affected:
up to 1.0.30
Fix:
No patched version reported
Disclosed:
Apr 1, 2025

CVE-2025-31793 on NVD →

Piotnet Forms [piotnetforms] < 1.0.30

unknown

[en] Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.

Affected:
up to 1.0.30
Fixed in:
1.0.30
Disclosed:
Jun 12, 2024

CVE-2023-51413 on NVD →

Piotnet Forms [piotnetforms] < 1.0.29

unknown

[en] The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's se...

Affected:
up to 1.0.29
Fixed in:
1.0.29
Disclosed:
Jan 11, 2024

CVE-2023-6220 on NVD →

Piotnet Forms [piotnetforms] < 1.0.29

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.

Affected:
up to 1.0.29
Fixed in:
1.0.29
Disclosed:
Dec 29, 2023

CVE-2023-51412 on NVD →

Piotnet Forms Plugin <= 1.0.28 - Unauthenticated Arbitrary File Upload

critical

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 1.0.28. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server w...

CVSS:
9.8
Affected:
up to 1.0.28
Fixed in:
1.0.29
Disclosed:
Dec 27, 2023

CVE-2023-51412 on NVD →

Piotnet Forms <= 1.0.25 - Missing Authorization via multiple AJAX actions

medium

The Piotnet Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 1.0.25. This makes it possible for unauthenticated attackers to save draft posts and download arbitrary JSON files f...

CVSS:
6.5
Affected:
up to 1.0.29
Fixed in:
1.0.30
Disclosed:
Dec 27, 2023

CVE-2023-51413 on NVD →

Piotnet Forms <= 1.0.28 - Unauthenticated Arbitrary File Upload

high

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.28. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server...

CVSS:
8.1
Affected:
up to 1.0.28
Fixed in:
1.0.29
Disclosed:
Dec 4, 2023

CVE-2023-6220 on NVD →

Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)

unknown
Affected:
up to 1.0.30
Fix:
No patched version reported

CVE-2025-57933 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database