๐Ÿ” CVE Alert

CVE-2026-96227

UNKNOWN 0.0

Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).

Vendor unknown
Product piotnet forms
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown piotnet forms

Be the first to know when new unknown vulnerabilities affecting unknown piotnet forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Piotnet Forms
0 โ‰ค 1.0.30

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/90756840-b277-41bd-8104-16f839db5189/

Credits

Claude Ndanda (TrixX) WPScan