PT-2025-47259 · WordPress · Pie Forms For Wp

CVE-2025-12528

·

Published

2025-11-18

·

Updated

2025-11-23

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pie Forms for WP plugin for WordPress versions prior to 1.7
Description The Pie Forms for WP plugin for WordPress is susceptible to an Arbitrary File Upload issue through the format classic function. Insufficient file type validation within the validate classic method allows attackers to upload files with dangerous extensions, such as PHP, potentially leading to remote code execution. Exploitation requires guessing the file upload directory, and the file name is generated using a secure hash method.
Recommendations Update the Pie Forms for WP plugin to version 1.7 or later.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-12528

Affected Products

Pie Forms For Wp