plugin

Mw Wp Form Vulnerabilities

11 known security issues reported for the Mw Wp Form WordPress plugin. Most recent disclosed Jun 9, 2026.

1 critical 5 high 5 medium

Running Mw Wp Form on your site? Check whether your installed version is affected.

Scan your site free

MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter

medium

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary we...

CVSS:
4.4
Affected:
up to 5.1.3
Fixed in:
5.1.4
Disclosed:
Jun 9, 2026

CVE-2026-8853 on NVD →

MW WP Form <= 5.1.3 - Unauthenticated Stored Cross-Site Scripting

high

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...

CVSS:
7.2
Affected:
up to 5.1.3
Fixed in:
5.1.4
Disclosed:
Jun 1, 2026

CVE-2026-48871 on NVD →

MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter

medium

The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password...

CVSS:
5.3
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
May 13, 2026

CVE-2026-6206 on NVD →

MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys

high

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() — a function that returns abso...

CVSS:
8.1
Affected:
up to 5.1.1
Fixed in:
5.1.2
Disclosed:
Apr 8, 2026

CVE-2026-5436 on NVD →

MW WP Form - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir vulnerability

high

Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir vulnerability

CVSS:
8.1
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Apr 2, 2026

MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir

high

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrar...

CVSS:
8.1
Affected:
up to 5.1.0
Fixed in:
5.1.1
Disclosed:
Apr 1, 2026

CVE-2026-4347 on NVD →

MW WP Form <= 5.0.6 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will...

CVSS:
5.5
Affected:
up to 5.0.6
Fixed in:
5.1.0
Disclosed:
Jan 31, 2024

CVE-2024-24804 on NVD →

MW WP Form <= 5.0.3 - Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion

high

The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-...

CVSS:
7.5
Affected:
up to 5.0.3
Fixed in:
5.0.4
Disclosed:
Dec 15, 2023

CVE-2023-6559 on NVD →

MW WP Form <= 5.0.1 - Unauthenticated Arbitrary File Upload

critical

The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make...

CVSS:
9.8
Affected:
up to 5.0.1
Fixed in:
5.0.2
Disclosed:
Dec 4, 2023

CVE-2023-6316 on NVD →

MW WP Form <= 4.4.5 - Missing Authorization

medium

The MW WP Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 4.4.5. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 4.4.5
Fixed in:
5.0.0
Disclosed:
Oct 19, 2023

CVE-2023-46206 on NVD →

MW WP Form <= 4.4.2 - Directory Traversal via _file_upload

medium

The MW WP Form plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.4.2 via the _file_upload function. This allows unauthenticated attackers to upload files of allowed types to arbitrary directories on the site.

CVSS:
5.3
Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
May 8, 2023

CVE-2023-28409 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database