๐Ÿ” CVE Alert

CVE-2026-78363

MEDIUM 4.8

MW WP Form < 5.1.5 - Unauthenticated Arbitrary Shortcode Execution via Completion Message Merge Tags

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site. Exploitation requires the site to have been configured to echo a submitted value back to the visitor after submission.

Vendor unknown
Product mw wp form
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown mw wp form

Be the first to know when new medium vulnerabilities affecting unknown mw wp form are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / MW WP Form
0 < 5.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0569c5f7-2001-4364-a68b-451b73f3a32a/

Credits

Jakub Herman WPScan