Arbitrary File Upload Vulnerability in Piotnet Forms Plugin for WordPress
CVE-2026-4883
9.8CRITICAL
What is CVE-2026-4883?
The Piotnet Forms plugin for WordPress is susceptible to an arbitrary file upload vulnerability due to inadequate file type validation in the 'piotnetforms_ajax_form_builder' function. The plugin's extension blacklist is insufficient, as it only blocks certain extensions (php, phpt, php5, php7, exe) but permits the upload of potentially harmful file types like .phar and .phtml. This flaw enables unauthenticated attackers to leverage file fields within forms to upload arbitrary files on the server, raising concerns for potential remote code execution.
Affected Version(s)
Piotnet Forms 0 <= 2.1.40