Piotnet Forms WordPress Plugin Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the Piotnet Forms plugin for WordPress, affecting all versions through 2.1.40. The issue arises from inadequate file type validation in the 'piotnetforms_ajax_form_builder' function. The plugin's extension blacklist only partially restricts certain file types, allowing potentially dangerous extensions like .phar and .phtml to be uploaded. This flaw could enable unauthenticated attackers to upload arbitrary files to the server, potentially leading to remote code execution, especially if a file field is included in the form.

Impact

Exploitation of this vulnerability could result in unauthorized file uploads, with the potential for those files to be executed on the server, leading to remote code execution.

Added: May 19, 2026, 1:19 PM
Updated: May 19, 2026, 1:19 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
7.6
remediation
0.0
relevance
8.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.