Sceawere

Vulnerability Detail

CVE-2026-96227UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Piotnet Forms Unauthenticated Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
8h ago
Vendor
Unknown
Product
Piotnet Forms
Attack Type
CWE-79 Cross-Site Scripting (XSS)
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-11T07:17:29.543Z",
  "pubdate": "2026-10-11T07:17:29.543Z",
  "executiveSummary": "A security vulnerability has been identified in the Piotnet Forms WordPress plugin, affecting all versions up to and including 1.0.30. The vulnerability stems from a total lack of authentication and validation on file upload requests submitted through the plugin's form handling component. Unauthenticated remote attackers can exploit this flaw by uploading browser-renderable files containing malicious executable code.\nBecause the application stores these files in a web-accessible directory without verifying the uploader's identity or restricting permitted file types, the attack results in Stored Cross-Site Scripting (XSS). When a target user or site administrator opens the uploaded file URL, the embedded JavaScript executes in the context of the site's origin.\nThe risk implications are severe, as the vulnerability requires no privileges or authentication to exploit. Successful exploitation enables attackers to execute arbitrary client-side code, hijack user session cookies, perform unauthorized actions on behalf of administrative users, and potentially compromise the security posture of the host WordPress installation.",
  "technicalDetails": "The Piotnet Forms plugin for WordPress (versions <= 1.0.30) fails to enforce access control checks and server-side file inspection on form-submission file-upload requests. When a user submits a form containing a file upload field, the request is processed by a server-side handler that accepts incoming multipart form-data. This handler fails to verify whether the requesting user possesses valid authentication credentials or session tokens, making the endpoint publicly accessible to unauthenticated remote entities.\nFurthermore, the root cause includes missing file extension and MIME-type validation during request processing. The plugin does not restrict file types to safe formats, nor does it sanitize uploaded filenames or block browser-renderable file extensions such as HTML or SVG. Consequently, an attacker can transmit files containing arbitrary JavaScript within `<script>` tags or event handlers.\nThe complete attack flow proceeds through the following phases:\n1. Endpoint Targeting: The attacker identifies an instance of the Piotnet Forms plugin (version 1.0.30 or earlier) on a target WordPress site.\n2. Payload Crafting: The attacker generates a file containing arbitrary JavaScript, formatted as an HTML document or an SVG image.\n3. Unauthenticated Upload: The attacker transmits an HTTP POST request containing the malicious file to the form submission upload endpoint without providing authentication credentials.\n4. Insecure Storage: The server-side code executes without validating the requester or the file type, storing the payload file directly within a publicly accessible directory on the web server.\n5. Triggering Execution: The attacker directly accesses or tricks an authenticated victim or site administrator into navigating to the direct URL of the stored file.\n6. Script Rendering: The web server serves the static file. Because the application lacks protective headers such as 'Content-Disposition: attachment' or restrictive Content Security Policies (CSP), the target user's web browser automatically renders the file and executes the embedded JavaScript under the site's domain origin.\nPost-exploitation capabilities allow the attacker to read and manipulate DOM elements, exfiltrate sensitive administrative cookies or CSRF tokens, issue unauthorized API requests under the victim's session, and potentially achieve full administrative takeover of the WordPress instance."
}
CVE-2026-96227: Piotnet Forms Unauthenticated Stored XSS (HIGH Severity, CVSS: 8.8) | Sceawere