PT-2026-83526 · WordPress · Mw Wp Form

CVE-2026-78364

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MW WP Form versions prior to 5.1.6
Description Insufficient sanitization and escaping of form settings before they are output on an admin dashboard page allows users with Editor privileges or higher to execute Stored Cross-Site Scripting (XSS) attacks against high-privilege users, such as administrators. Stored XSS occurs when a malicious script is permanently stored on the target server and later executed in the browser of a victim viewing the affected page.
Recommendations Update MW WP Form to version 5.1.6 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78364

Affected Products

Mw Wp Form