CVE-2026-1056, a critical vulnerability, affects the Snow Monkey Forms plugin for WordPress in all versions up to and including 12.0.3. The vulnerability allows unauthenticated attackers to delete arbitrary files on the server. Successful exploitation can remove critical site files (for example wp-config.php), leading to remote code execution, data loss, and full site compromise.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

