PT-2025-47259 · WordPress · Pie Forms For Wp

Published

2025-11-18

·

Updated

2025-11-23

·

CVE-2025-12528

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pie Forms for WP plugin for WordPress versions prior to 1.7
Description The Pie Forms for WP plugin for WordPress is susceptible to an Arbitrary File Upload issue through the format classic function. Insufficient file type validation within the validate classic method allows attackers to upload files with dangerous extensions, such as PHP, potentially leading to remote code execution. Exploitation requires guessing the file upload directory, and the file name is generated using a secure hash method.
Recommendations Update the Pie Forms for WP plugin to version 1.7 or later.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-12528

Affected Products

Pie Forms For Wp