Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload
criticalThe Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, w...
- CVSS:
- 9.8
- Affected:
- up to 2.1.40
- Fix:
- No patched version reported
- Disclosed:
- May 18, 2026