CVE-2026-4883 is an arbitrary file upload vulnerability in the Piotnet Forms plugin for WordPress affecting all versions up to and including 2.1.40. The flaw is caused by missing file type validation in the piotnetforms_ajax_form_builder function. The plugin relies on an incomplete extension blacklist that blocks only a limited set of extensions, while permitting other executable or dangerous file types such as PHAR- or PHTML-based payloads. As a result, an unauthenticated attacker can upload arbitrary files to the server through a vulnerable form configuration. In environments where uploaded files can be executed or otherwise processed in a dangerous manner by the web stack, the vulnerability may lead to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
piotnetforms_ajax_form_builder. Ensure the fixed release is deployed across all affected instances.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact exploit package for CVE-2026-4883 affecting Piotnet Forms Pro <= 2.1.40 on WordPress. It contains three files: a README describing the vulnerability and usage, a Python exploit script (shadow.py), and a PHP/.phtml web shell payload (shadow.phtml). The exploit chain described and implemented is an unauthenticated arbitrary file upload leading to remote code execution. The vulnerable plugin exposes the piotnetforms_ajax_form_builder AJAX handler to unauthenticated users and only blocks a small set of extensions (.php, .phpt, .php5, .php7, .exe). The exploit abuses allowed alternative executable extensions such as .phtml, prepending GIF89a bytes to improve bypass reliability. The README also notes a second unauthenticated AJAX action, piotnetforms_export_form_submission, which can leak the final uploaded file URL, completing the RCE chain. shadow.py is the main exploit. From the visible code and README, it supports single-target and mass-target operation, asynchronous concurrency via asyncio/httpx, version checking, automatic discovery of form parameters from HTML hidden inputs, upload attempts, shell URL verification, and result logging to shell.txt. It accepts a single URL or a file of targets, supports configurable thread/concurrency counts, and can use either the bundled shell or a custom payload file. The script is operational rather than a simple detector because it attempts exploitation and validates execution. shadow.phtml is the payload web shell. It is a GIF89a polyglot PHP script that exposes two core capabilities after upload: executing arbitrary OS commands supplied through the cmd query parameter, and uploading additional files into the same directory through a POST form field named f. It also prints a direct URL to any uploaded follow-on file. Overall, the repository's purpose is offensive exploitation of a WordPress plugin vulnerability to gain unauthenticated web shell access on vulnerable sites, with both interactive and bulk-scanning workflows.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.