200K Sites at Risk: Arbitrary File Move Flaw in MW WP Form

Date:

Vulnerability Report: Arbitrary File Move in MW WP Form Plugin

On March 16, 2026, a serious security vulnerability was reported in the MW WP Form plugin, which has over 200,000 active installations. This flaw allows unauthorized users to move critical files on a WordPress site, including the sensitive wp-config.php file, potentially leading to complete site takeover.

The vulnerability affects versions 5.1.0 and earlier and can be exploited when the “Saving inquiry data in database” option is enabled. Affected users are urged to update to version 5.1.1, which addresses this issue.

The risk level associated with this vulnerability is high, with a CVSS score of 8.1. Thanks to researcher ISMAILSHADOW for discovering and reporting this flaw, and to the developers for promptly releasing a fix.

For further protection, Wordfence users are safeguarded against such exploits through built-in firewall protections.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

In recent weeks, hackers have escalated their attacks on...