CVE-2026-4883Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-19: 1Mentions · 2026-06-05: 1Patch / Workaround · 2026-05-19: 1Technical Details · 2026-05-19: 105-1906-05
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-191
Patch1
2026-06-051
General1
Full discourse2 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-4883 Piotnet Formsに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/01/%e3%80%90%e7%b7%8a%e6%80%a5%e3%80%91cve-2026-4883-piotnet-forms%e3%81%ab%e6%b7%b1%e5%88%bb%e3%81%aa%e8%84%86%e5%bc%b1%e6%80%a7%ef%bd%9c%e5%8d%b3%e6%99%82%e5%af%be%e5%bf%9c%e3%81%8c%e5%bf%85%e8%a6%81/ #IT #Security #cybersecurity

    Post summary

    The snippet alerts to a severe vulnerability in Piotnet Forms (CVE-2026-4883) and urges immediate action, but lacks explicit details on exploits, patches, or technical specifics.

    0001060
    209 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-4883 — CVSS 9.8/10 ██████████ The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/AaFnUZOo9r

    Post summary

    The tweet announces the discovery of CVE-2026-4883 with a high severity score, highlights an arbitrary file upload flaw, and urges users to apply the available patch.

    1000083
    42 followersView on X

Explore more