top of page
perceptive_background_267k.jpg

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' func…

Published:

27 January 2026 at 23:00:00

Alert date:

28 January 2026 at 14:04:26

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

The Snow Monkey Forms plugin for WordPress contains a critical vulnerability allowing arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function. All versions up to and including 12.0.3 are affected. Unauthenticated attackers can exploit this to delete arbitrary files on the server, potentially leading to remote code execution when critical files like wp-config.php are deleted. The vulnerability stems from improper input validation in the file path handling mechanism.

Technical details

Mitigation steps:

Affected products:

Snow Monkey Forms WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page