Vulnerability Description
The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.
CVSS Score
MEDIUM
References
FAQ
What is CVE-2026-9815?
CVE-2026-9815 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, all...
How severe is CVE-2026-9815?
CVE-2026-9815 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-9815?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.