Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-56058: Quform <= 2.23.0: Unrestricted File Upload in Quform
CVE-2026-56058
Summary
Quform, a WordPress plugin, allows attackers to upload any file on the server. This can lead to unauthorized data access or server compromise. Update Quform to version 2.24.0 or later to fix this issue.
Original title
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
Original description
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
nvd CVSS3.1
9.9
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 26 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026