PT-2026-84124 · WordPress · Mw Wp Form

·

CVE-2026-78363

·

Published

2026-09-01

·

Updated

2026-09-01

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MW WP Form versions prior to 5.1.5
Description An issue exists where user-submitted values containing shortcodes are not properly sanitized before being merged into a message that is subsequently processed for shortcodes. This allows unauthenticated users to execute any shortcode registered on the site. This occurs when the site is configured to echo a submitted value back to the visitor after submission.
Recommendations Update MW WP Form to version 5.1.5 or later.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78363

Affected Products

Mw Wp Form