Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Stored XSS.This issue affects Piotnet Forms: from n/a through <= 1.0.30.
Published: 2025-04-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, leading to a stored cross‑site scripting flaw in the Piotnet Forms plugin. When a malicious script is entered into a form field, the plugin saves the data and later serves it to other users without proper escaping. This flaw is identified as CWE‑79. Successful exploitation would allow an attacker to run arbitrary JavaScript in the victim’s browser, potentially causing session hijacking, credential theft, or defacement.

Affected Systems

All installations of the Piotnet Forms plugin for WordPress with a version number of 1.0.30 or earlier are affected. No other versions are currently known to be vulnerable.

Risk and Exploitability

The CVSS base score of 5.9 indicates moderate severity for a stored XSS flaw, while the EPSS score of less than 1% shows a very low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a submitted form entry that an attacker can manipulate; this inference is drawn because the flawed sandboxing occurs when form data is stored and later displayed to site visitors.

Generated by OpenCVE AI on May 1, 2026 at 11:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Piotnet Forms plugin to version 1.0.31 or later.
  • Implement server‑side sanitization or output escaping for all form fields that accept user input.
  • If an update cannot be applied immediately, disable or uninstall the plugin or restrict form submission to trusted users only.

Generated by OpenCVE AI on May 1, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9242 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms piotnetforms allows Stored XSS.This issue affects Piotnet Forms: from n/a through <= 1.0.30.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in piotnetdotcom Piotnet Forms allows Stored XSS. This issue affects Piotnet Forms: from n/a through 1.0.30.
Title WordPress Piotnet Forms plugin <= 1.0.30 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.919Z

Reserved: 2025-04-01T13:20:05.024Z

Link: CVE-2025-31793

cve-icon Vulnrichment

Updated: 2025-04-01T19:48:11.179Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:17.440

Modified: 2026-04-23T15:28:18.363

Link: CVE-2025-31793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')