Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-1056-POC — Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) | Kitploit
Tools/GitHubGitHub/ch4r0nn/cve-2026-1056-poc
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubch4r0nn/cve-2026-1056-poc

CVE-2026-1056-POC

Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)

View Repository
698 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-1056-POC

Snow Monkey Forms - Unauthenticated Arbitrary File Deletion PoC

This repository contains a Proof of Concept (PoC) for a critical vulnerability in the Snow Monkey Forms WordPress plugin (versions <= 12.0.3). The vulnerability allows an unauthenticated attacker to delete arbitrary files on the server via Path Traversal.

Refer: Sarawut Poolkhet (MisterHelloz)

Vulnerability Details

  • Type: Arbitrary File Deletion / Path Traversal
  • Component: Snow_Monkey\Plugin\Forms\App\Rest\Route\View.php
  • Method: REST API (/wp-json/snow-monkey-form/v1/view)
  • Authentication: Unauthencation

Vulnerability Analysis

1. Entry Point & Logic Bypass

The vulnerability resides in the REST API handler located at Snow_Monkey\Plugin\Forms\App\Rest\Route\View.php. The send() method dictates the flow based on user input parameters.

// File: App/Rest/Route/View.php

public function send() {
    Csrf::save_token();
    $method = Meta::get_method(); // Sourced from $_POST['snow-monkey-forms-meta']['method']

    // VULNERABILITY: If 'method' is 'input', the critical CSRF check is BYPASSED.
    if ( 'input' === $method ) {
        return $this->_send(); // Direct execution flow to _send()
    }

    // CSRF check is only performed for other methods (e.g., 'confirm', 'complete')
    if ( ! Csrf::validate( Meta::get_token() ) ) { ... }

By supplying input as the method parameter, an attacker forces the application to execute the _send() function immediately, skipping the Csrf::validate() security control intended to prevent unauthorized actions.

2. Path Traversal Injection

Inside the _send() method, the application attempts to perform a cleanup routine for user-specific temporary directories. This routine relies on the formid parameter.

// File: App/Rest/Route/View.php -> _send()

// 'form_id' is sourced directly from POST data via Meta class without sanitization
$user_dirpath = Directory::generate_user_dirpath( $this->setting->get( 'form_id' ), false );

Directory::do_empty( $user_dirpath, true ); // Recursively delete contents
Directory::remove( $user_dirpath );         // Delete the directory itself

The critical flaw lies in how Directory::generate_user_dirpath constructs the path:

// File: App/Model/Directory.php

public static function generate_user_dirpath( $form_id, $do_create_directory = true ) {
    $saved_token = Csrf::saved_token();
    // ... (Regex check for token exists, but not for form_id) ...

    $user_dir = path_join( static::get(), $saved_token );
    
    // VULNERABILITY: $form_id is appended directly. 
    // WordPress path_join() does NOT resolve or sanitize '../' sequences.
    $user_dir = path_join( $user_dir, (string) $form_id ); 

    return $user_dir;
}

The $form_id variable is cast to a string but is never validated to be an integer. This allows an attacker to inject directory traversal characters (e.g., ../../../../).

Usage

  • Find version http://site-wordpress.com/wp-content/plugins/snow-monkey-forms/readme.txt

Prerequisites

  • Python 3.x
  • requests library (pip install requests)

Command

python exploit.py -u <TARGET_URL> -f <TRAVERSAL_PAYLOAD>
CVE-2026-1056-POC
Download Tool