PT-2026-5121 · WordPress · Snow Monkey Forms
Sarawut Poolkhet
·
Published
2026-01-28
·
Updated
2026-01-30
·
CVE-2026-1056
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snow Monkey Forms versions up to and including 12.0.3
Description
The Snow Monkey Forms plugin for WordPress is susceptible to arbitrary file deletion. Insufficient file path validation within the
generate user dirpath function allows unauthenticated attackers to delete arbitrary files on the server. Successful deletion of specific files, such as wp-config.php, could lead to remote code execution.Recommendations
Versions prior to and including 12.0.3 should be updated to a newer, fixed version when available. As a temporary workaround, consider restricting access to the
generate user dirpath function until a patch is available.Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snow Monkey Forms