CVE-2026-96227 PUBLISHED

Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload

Assigner: WPScan
Reserved: 22.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).

Product Status

Vendor Unknown
Product Piotnet Forms
Versions Default: unknown
  • affected from 0 to 1.0.30 (incl.)

Credits

  • Claude Ndanda (TrixX) finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE