CVE-2026-78364
Received Received - Intake

Stored XSS in MW WP Form WordPress Plugin

Vulnerability report for CVE-2026-78364, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: WPScan

Description

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mw_wp_form mw_wp_form to 5.1.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored Cross-Site Scripting (XSS) flaw in the MW WP Form WordPress plugin before version 5.1.6. It occurs because the plugin does not properly sanitize or escape form settings before displaying them in an admin dashboard page. This allows users with Editor-level access or higher to inject malicious scripts that target high-privilege users like administrators.

Detection Guidance

Check the installed version of the MW WP Form plugin. If it is below 5.1.6, the system is vulnerable. Use WordPress admin dashboard or run a command like 'wp plugin list' if using WP-CLI to verify the version.

Impact Analysis

If exploited, this vulnerability could allow attackers with Editor access to inject malicious scripts into admin dashboard pages. When high-privilege users like administrators view these pages, the scripts could execute, potentially leading to unauthorized actions, data theft, or further compromise of the WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, which may violate compliance requirements under GDPR or HIPAA. Stored XSS attacks could expose sensitive user data, resulting in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Update the MW WP Form plugin to version 5.1.6 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78364. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart