Piotnet Forms Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in the Piotnet Forms WordPress plugin, affecting versions through 1.0.30. This vulnerability allows for improper limitation of a pathname, potentially leading to unauthorized access to restricted directories.

Impact

Exploitation of this vulnerability allows for path traversal, which could lead to unauthorized file access on the server.

Remediation

Users are advised to update to a version of the Piotnet Forms plugin that is later than 1.0.30. For those unable to update, Patchstack has issued a virtual patch that can be applied.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
3.3
exploitability
5.4
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.