PT-2026-50647 · WordPress · Magicform
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MagicForm versions prior to 0.1.4
Description
The MagicForm WordPress plugin fails to properly validate file types uploaded via an unauthenticated AJAX action. This occurs when a form's per-field extension allowlist is left empty, enabling unauthenticated attackers to upload PHP files and execute arbitrary code on the server.
Recommendations
Update to a version later than 0.1.3.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Magicform