Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Stored XSS.This issue affects Piotnet Forms: from n/a through <= 1.0.30.
Published: 2025-04-01
Score: 5.9 Medium
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows attackers to store malicious JavaScript in the Piotnet Forms plugin. Once injected, the code executes in the browsers of visitors who view the affected form page, potentially enabling session hijacking, cookie theft, or defacement of the site. The flaw is a classic Cross‑Site Scripting flaw (CWE‑79).

Affected Systems

WordPress sites using the Piotnet Forms plugin from any version up to and including 1.0.30 are affected; later versions contain a fix.

Risk and Exploitability

The CVSS score of 5.9 reflects a moderate impact when the attack succeeds. The EPSS score of less than 1 % suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description of stored XSS, involves posting malicious payloads through free‑form fields in the plugin’s forms and then tricking or enticing users to visit the pages that render the stored data.

Generated by OpenCVE AI on May 1, 2026 at 11:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Piotnet Forms to the latest version that contains the fix; this removes the stored‑XSS flaw.
  • If an upgrade is impossible, restrict or strip user input in the forms, for example by disabling the free‑text field or applying stricter filtering before rendering.
  • After remediation, run a full XSS scan of the site to confirm that the vulnerable input vectors no longer exist.

Generated by OpenCVE AI on May 1, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9234 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Stored XSS.This issue affects Piotnet Forms: from n/a through <= 1.0.30.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
Title WordPress Piotnet Forms plugin <= 1.0.30 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.979Z

Reserved: 2025-04-01T13:20:05.024Z

Link: CVE-2025-31792

cve-icon Vulnrichment

Updated: 2025-04-01T19:49:56.239Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:17.290

Modified: 2026-04-23T15:28:18.250

Link: CVE-2025-31792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')