6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Description
The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.
Basic Information
ID
CVE-2026-9815
Source
WPScan
Published
Jun 18, 2026 at 06:00
Modified
Jun 18, 2026 at 13:15
Affected Product
Vendor
Unknown
Product
MagicForm
Affected Versions
Unknown MagicForm 0