CVE-2026-96227: Piotnet Forms <= 1.0.30 - Unauthenticated Stored XSS via File Upload
The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker does not need to authenticate. They need to be able to submit a file-upload request to a vulnerable Piotnet Forms installation.
What must happen for the stored JavaScript to execute?
The attacker-uploaded browser-renderable file must be opened. When opened, it can execute arbitrary JavaScript in the site's origin.
Are installations through version 1.0.30 affected?
The issue affects Piotnet Forms through version 1.0.30. The provided information does not identify a fixed version.
How can I determine whether my site may be affected?
Check whether Piotnet Forms is installed and whether its version is 1.0.30 or earlier. Also review whether the plugin accepts unauthenticated form-submission file-upload requests and stores browser-renderable file types.