MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter
medium
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary we...
- CVSS:
- 4.4
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- Jun 9, 2026
CVE-2026-8853 on NVD →
MW WP Form <= 5.1.3 - Unauthenticated Stored Cross-Site Scripting
high
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an...
- CVSS:
- 7.2
- Affected:
- up to 5.1.3
- Fixed in:
- 5.1.4
- Disclosed:
- Jun 1, 2026
CVE-2026-48871 on NVD →
MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter
medium
The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password...
- CVSS:
- 5.3
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- May 13, 2026
CVE-2026-6206 on NVD →
MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys
high
The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field key) passed to the generate_user_file_dirpath() function, which uses WordPress's path_join() — a function that returns abso...
- CVSS:
- 8.1
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.2
- Disclosed:
- Apr 8, 2026
CVE-2026-5436 on NVD →
MW WP Form - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir vulnerability
high
Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir vulnerability
- CVSS:
- 8.1
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.1
- Disclosed:
- Apr 2, 2026
MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir
high
The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrar...
- CVSS:
- 8.1
- Affected:
- up to 5.1.0
- Fixed in:
- 5.1.1
- Disclosed:
- Apr 1, 2026
CVE-2026-4347 on NVD →
MW WP Form <= 5.0.6 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 5.5
- Affected:
- up to 5.0.6
- Fixed in:
- 5.1.0
- Disclosed:
- Jan 31, 2024
CVE-2024-24804 on NVD →
MW WP Form <= 5.0.3 - Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion
high
The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-...
- CVSS:
- 7.5
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.4
- Disclosed:
- Dec 15, 2023
CVE-2023-6559 on NVD →
MW WP Form <= 5.0.1 - Unauthenticated Arbitrary File Upload
critical
The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and including, 5.0.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make...
- CVSS:
- 9.8
- Affected:
- up to 5.0.1
- Fixed in:
- 5.0.2
- Disclosed:
- Dec 4, 2023
CVE-2023-6316 on NVD →
MW WP Form <= 4.4.5 - Missing Authorization
medium
The MW WP Form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 4.4.5. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 5.3
- Affected:
- up to 4.4.5
- Fixed in:
- 5.0.0
- Disclosed:
- Oct 19, 2023
CVE-2023-46206 on NVD →
MW WP Form <= 4.4.2 - Directory Traversal via _file_upload
medium
The MW WP Form plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.4.2 via the _file_upload function. This allows unauthenticated attackers to upload files of allowed types to arbitrary directories on the site.
- CVSS:
- 5.3
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- May 8, 2023
CVE-2023-28409 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database