Piotnet Forms <= 1.0.30 - Cross-Site Request Forgery
medium
The Piotnet Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.30. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can tr...
- CVSS:
- 4.3
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Sep 22, 2025
CVE-2025-57933 on NVD →
Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms. This issue affects Piotnet Forms: from n/a through 1.0.30.
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2025
CVE-2025-32205 on NVD →
Piotnet Forms <= 1.0.30 - Authenticated (Editor+) Path Traversal
low
The Piotnet Forms plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.30. This makes it possible for authenticated attackers, with Editor-level access and above, to perform actions on files outside of the originally intended directory.
- CVSS:
- 3.8
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Apr 7, 2025
CVE-2025-32205 on NVD →
Piotnet Forms <= 1.0.30 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Piotnet Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that w...
- CVSS:
- 6.4
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31792 on NVD →
Piotnet Forms <= 1.0.30 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The Piotnet Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 1.0.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary web s...
- CVSS:
- 4.4
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31793 on NVD →
Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31792 on NVD →
Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
- Disclosed:
- Apr 1, 2025
CVE-2025-31793 on NVD →
Piotnet Forms [piotnetforms] < 1.0.30
unknown
[en] Missing Authorization vulnerability in Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.29.
- Affected:
- up to 1.0.30
- Fixed in:
- 1.0.30
- Disclosed:
- Jun 12, 2024
CVE-2023-51413 on NVD →
Piotnet Forms [piotnetforms] < 1.0.29
unknown
[en] The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's se...
- Affected:
- up to 1.0.29
- Fixed in:
- 1.0.29
- Disclosed:
- Jan 11, 2024
CVE-2023-6220 on NVD →
Piotnet Forms [piotnetforms] < 1.0.29
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.
- Affected:
- up to 1.0.29
- Fixed in:
- 1.0.29
- Disclosed:
- Dec 29, 2023
CVE-2023-51412 on NVD →
Piotnet Forms Plugin <= 1.0.28 - Unauthenticated Arbitrary File Upload
critical
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 1.0.28. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server w...
- CVSS:
- 9.8
- Affected:
- up to 1.0.28
- Fixed in:
- 1.0.29
- Disclosed:
- Dec 27, 2023
CVE-2023-51412 on NVD →
Piotnet Forms <= 1.0.25 - Missing Authorization via multiple AJAX actions
medium
The Piotnet Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 1.0.25. This makes it possible for unauthenticated attackers to save draft posts and download arbitrary JSON files f...
- CVSS:
- 6.5
- Affected:
- up to 1.0.29
- Fixed in:
- 1.0.30
- Disclosed:
- Dec 27, 2023
CVE-2023-51413 on NVD →
Piotnet Forms <= 1.0.28 - Unauthenticated Arbitrary File Upload
high
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'piotnetforms_ajax_form_builder' function in versions up to, and including, 1.0.28. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server...
- CVSS:
- 8.1
- Affected:
- up to 1.0.28
- Fixed in:
- 1.0.29
- Disclosed:
- Dec 4, 2023
CVE-2023-6220 on NVD →
Piotnet Forms [piotnetforms] <= 1.0.30 (unfixed)
unknown
- Affected:
- up to 1.0.30
- Fix:
- No patched version reported
CVE-2025-57933 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database