PT-2026-102705 · WordPress · Balbooa Forms
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Balbooa Forms versions prior to 2.4.3.4
Description
The final form submission processes JSON arrays for each upload field but only verifies that IDs are numeric. Because client-supplied filenames and display names are trusted directly, the system is susceptible to metadata tampering, cross-session claiming, and path traversal risks, specifically through the
getFilePath() function.Recommendations
Update Balbooa Forms to version 2.4.3.4 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Balbooa Forms