← All CVEs NewScan detects
low

CVE-2026-78364

MW WP Form stored cross-site scripting - form settings are echoed unescaped in an admin dashboard page

Severity
low
Affected product
mw-wp-form
Affected versions
mw-wp-form < 5.1.6
Fixed in
mw-wp-form 5.1.6
Added to NewScan
2026-08-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints mw-wp-form from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-30 (/daily-cve). Same generic slug->readme.txt version source; slug verified against api.wordpress.org ('MW WP Form', current 5.1.6 - the fix release). Low, and deliberately: the payload is written through the plugin's own settings, so it needs contributor-or-above and only fires for an administrator visiting that settings screen. Recorded because that is still an escalation path from a low-privilege author to the administrator session, not because it is remotely triggerable.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →