Vulnerability Report: Arbitrary File Move in MW WP Form Plugin
On March 16, 2026, a serious security vulnerability was reported in the MW WP Form plugin, which has over 200,000 active installations. This flaw allows unauthorized users to move critical files on a WordPress site, including the sensitive wp-config.php file, potentially leading to complete site takeover.
The vulnerability affects versions 5.1.0 and earlier and can be exploited when the “Saving inquiry data in database” option is enabled. Affected users are urged to update to version 5.1.1, which addresses this issue.
The risk level associated with this vulnerability is high, with a CVSS score of 8.1. Thanks to researcher ISMAILSHADOW for discovering and reporting this flaw, and to the developers for promptly releasing a fix.
For further protection, Wordfence users are safeguarded against such exploits through built-in firewall protections.
Source: View Original Report
