๐Ÿ” CVE Alert

CVE-2023-6559

HIGH 7.5

MW WP Form <= 5.0.3 - Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.

CWE CWE-22
Vendor inc2734
Product mw wp form
Published Dec 16, 2023
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for inc2734 mw wp form

Be the first to know when new high vulnerabilities affecting inc2734 mw wp form are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

inc2734 / MW WP Form
0 โ‰ค 5.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/412d555c-9bbd-42f5-8020-ccfc18755a79?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3007879/mw-wp-form

Credits

Thomas Sanzey