CVE-2026-1056General

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-01-28); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-01-28: 2Mentions · 2026-01-29: 2Mentions · 2026-01-30: 1PoC Mentioned / Linked · 2026-01-29: 2Exploit Tool / Code · 2026-01-29: 2Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 201-2801-2901-30
Signal classification3 categories
General
240.0%
PoC
240.0%
Disclosure
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure1General1
2026-01-292
PoC2
2026-01-301
General1
Full discourse5 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-1056: Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal PoC/Exploit: https://github.com/ch4r0nn/CVE-2026-1056-POC CVSS: 9.8 CVE Published: January 28th, 2026 Advisory: https://github.com/advisories/GHSA-g5p3-f4cq-94v5 https://t.co/Y5p6a1eyfI

    Post summary

    CVE-2026-1056 is a critical path‑traversal flaw in Snow Monkey Forms <=12.0.3 that permits unauthenticated arbitrary file deletion; a PoC/exploit is publicly available on GitHub.

    25016124.6K
    165.7K followersView on X
  • Clandestine@akaclandestine
    PoC

    GitHub - ch4r0nn/CVE-2026-1056-POC: Snow Monkey Forms &lt;= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) https://github.com/ch4r0nn/CVE-2026-1056-POC

    Post summary

    A GitHub repository hosts a PoC demonstrating unauthenticated arbitrary file deletion via path traversal in Snow Monkey Forms <=12.0.3 (CVE-2026-1056); no evidence of active exploitation or patch availability is provided.

    0601561.5K
    55.0K followersView on X
  • VulnTracker@vuln_tracker
    General

    @DarkWebInformer You now can see the full details about CVE-2026-1056 for free on https://vulntracker.io/cves/CVE-2026-1056

    Post summary

    The tweet shares a link to a public vulnerability tracker page for CVE-2026-1056, providing full details but no additional context such as PoC, exploitation status, or patch information.

    00010105
    335 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1056 Unauthenticated Arbitrary File Deletion Vulnerability in Snow Monkey Forms WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1056

    Post summary

    A newly disclosed CVE (CVE-2026-1056) identifies an unauthenticated arbitrary file deletion vulnerability in the Snow Monkey Forms WordPress plugin, but no PoC, exploit, mitigation, or active exploitation evidence is provided.

    0000071
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1056: CRITICAL] WordPress Snow Monkey Forms plugin (up to 12.0.3) has a serious security flaw allowing attackers to delete files on servers, potentially leading to remote code execution.#cve,CVE-2026-1056,#cybersecurity https://cvefind.com/CVE-2026-1056

    Post summary

    The tweet announces a critical vulnerability in the Snow Monkey Forms WordPress plugin that enables attackers to delete server files and potentially achieve remote code execution, with no evidence of active exploitation or a fix mentioned.

    0000082
    584 followersView on X

Explore more