Sceawere
Vulnerability Detail
CVE-2026-96227UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Piotnet Forms Unauthenticated Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Piotnet Forms
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:29.543Z",
"pubdate": "2026-10-11T07:17:29.543Z",
"executiveSummary": "A security vulnerability has been identified in the Piotnet Forms WordPress plugin, affecting all versions up to and including 1.0.30. The vulnerability stems from a total lack of authentication and validation on file upload requests submitted through the plugin's form handling component. Unauthenticated remote attackers can exploit this flaw by uploading browser-renderable files containing malicious executable code.\nBecause the application stores these files in a web-accessible directory without verifying the uploader's identity or restricting permitted file types, the attack results in Stored Cross-Site Scripting (XSS). When a target user or site administrator opens the uploaded file URL, the embedded JavaScript executes in the context of the site's origin.\nThe risk implications are severe, as the vulnerability requires no privileges or authentication to exploit. Successful exploitation enables attackers to execute arbitrary client-side code, hijack user session cookies, perform unauthorized actions on behalf of administrative users, and potentially compromise the security posture of the host WordPress installation.",
"technicalDetails": "The Piotnet Forms plugin for WordPress (versions <= 1.0.30) fails to enforce access control checks and server-side file inspection on form-submission file-upload requests. When a user submits a form containing a file upload field, the request is processed by a server-side handler that accepts incoming multipart form-data. This handler fails to verify whether the requesting user possesses valid authentication credentials or session tokens, making the endpoint publicly accessible to unauthenticated remote entities.\nFurthermore, the root cause includes missing file extension and MIME-type validation during request processing. The plugin does not restrict file types to safe formats, nor does it sanitize uploaded filenames or block browser-renderable file extensions such as HTML or SVG. Consequently, an attacker can transmit files containing arbitrary JavaScript within `<script>` tags or event handlers.\nThe complete attack flow proceeds through the following phases:\n1. Endpoint Targeting: The attacker identifies an instance of the Piotnet Forms plugin (version 1.0.30 or earlier) on a target WordPress site.\n2. Payload Crafting: The attacker generates a file containing arbitrary JavaScript, formatted as an HTML document or an SVG image.\n3. Unauthenticated Upload: The attacker transmits an HTTP POST request containing the malicious file to the form submission upload endpoint without providing authentication credentials.\n4. Insecure Storage: The server-side code executes without validating the requester or the file type, storing the payload file directly within a publicly accessible directory on the web server.\n5. Triggering Execution: The attacker directly accesses or tricks an authenticated victim or site administrator into navigating to the direct URL of the stored file.\n6. Script Rendering: The web server serves the static file. Because the application lacks protective headers such as 'Content-Disposition: attachment' or restrictive Content Security Policies (CSP), the target user's web browser automatically renders the file and executes the embedded JavaScript under the site's domain origin.\nPost-exploitation capabilities allow the attacker to read and manipulate DOM elements, exfiltrate sensitive administrative cookies or CSRF tokens, issue unauthorized API requests under the victim's session, and potentially achieve full administrative takeover of the WordPress instance."
}