CVE-2026-9815

The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.
Configurations

No configuration.

History

18 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-18 08:16

Updated : 2026-06-22 18:38


NVD link : CVE-2026-9815

Mitre link : CVE-2026-9815

CVE.ORG link : CVE-2026-9815


JSON object : View

Products Affected

No product.

CWE

No CWE.