PT-2026-84124 · WordPress · Mw Wp Form
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MW WP Form versions prior to 5.1.5
Description
An issue exists where user-submitted values containing shortcodes are not properly sanitized before being merged into a message that is subsequently processed for shortcodes. This allows unauthenticated users to execute any shortcode registered on the site. This occurs when the site is configured to echo a submitted value back to the visitor after submission.
Recommendations
Update MW WP Form to version 5.1.5 or later.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mw Wp Form