Websoudan Mw Wp Form vulnerabilities
4 known vulnerabilities affecting websoudan/mw_wp_form.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-6206P4MEDIUMCVSS 5.3≤ 5.1.22026-05-14
CVE-2026-6206 [MEDIUM] CWE-639 CVE-2026-6206: The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and
The MW WP Form plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.1.2 via the _get_post_property_from_querystring() function due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft pos
nvd
CVE-2023-46206P4MEDIUMCVSS 5.3≥ n/a, ≤ 4.4.52025-01-02
CVE-2023-46206 [MEDIUM] CWE-862 CVE-2023-46206: Missing Authorization vulnerability in websoudan MW WP Form allows Exploiting Incorrectly Configured
Missing Authorization vulnerability in websoudan MW WP Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MW WP Form: from n/a through 4.4.5.
nvd
CVE-2024-24804P4MEDIUMCVSS 5.4≥ n/a, ≤ 5.0.62024-02-10
CVE-2024-24804 [MEDIUM] CWE-79 CVE-2024-24804: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in websoudan MW WP Form allows Stored XSS.This issue affects MW WP Form: from n/a through 5.0.6.
nvd
CVE-2026-8853P4MEDIUMCVSS 4.4≤ 5.1.32026-06-10
CVE-2026-8853 [MEDIUM] CWE-79 CVE-2026-8853: The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' para
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that will execu
nvd