CVE-2026-78364
MW WP Form stored cross-site scripting - form settings are echoed unescaped in an admin dashboard page
- Severity
- low
- Affected product
- mw-wp-form
- Affected versions
- mw-wp-form < 5.1.6
- Fixed in
- mw-wp-form 5.1.6
- Added to NewScan
- 2026-08-30
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints mw-wp-form from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source; slug verified against api.wordpress.org ('MW WP Form', current 5.1.6 - the fix release). Low, and deliberately: the payload is written through the plugin's own settings, so it needs contributor-or-above and only fires for an administrator visiting that settings screen. Recorded because that is still an escalation path from a low-privilege author to the administrator session, not because it is remotely triggerable.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →