CVE-2026-9815
EUVD-2026-3785218.06.2026, 08:16
The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension allowlist is left empty, allowing unauthenticated attackers to upload PHP files and execute arbitrary code on the server.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.