Arbitrary File Move vulnerability in MW WP Form
-
WARNING – This plug-in has an Arbitrary File Move vulnerability in MW WP Form, a WordPress plugin with more than 200,000 active installations. This vulnerability makes it possible for unauthenticated threat actors to move arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
UPDATE: 08 April 2026 07H27 (GMT+2)
The author has released versions 5.1.1 and 5.1.2 to address the Arbitrary File Move vulnerability (CVE-2026-4347). While the initial communication was difficult, I appreciate the prompt release of the security fixes. Users should update immediately to ensure their sites are protected.
You must be logged in to reply to this review.