CVE-2026-78364 PUBLISHED

MW WP Form < 5.1.6 - Editor+ Stored XSS via Inquiry Data List

Assigner: WPScan
Reserved: 24.08.2026 Published: 30.08.2026 Updated: 30.08.2026

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.

Product Status

Vendor Unknown
Product MW WP Form
Versions Default: unaffected
  • affected from 0 to 5.1.6 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE