200K Sites at Risk: Arbitrary File Move Flaw in MW WP Form

Date:

Vulnerability Report: Arbitrary File Move in MW WP Form Plugin

On March 16, 2026, a serious security vulnerability was reported in the MW WP Form plugin, which has over 200,000 active installations. This flaw allows unauthorized users to move critical files on a WordPress site, including the sensitive wp-config.php file, potentially leading to complete site takeover.

The vulnerability affects versions 5.1.0 and earlier and can be exploited when the “Saving inquiry data in database” option is enabled. Affected users are urged to update to version 5.1.1, which addresses this issue.

The risk level associated with this vulnerability is high, with a CVSS score of 8.1. Thanks to researcher ISMAILSHADOW for discovering and reporting this flaw, and to the developers for promptly releasing a fix.

For further protection, Wordfence users are safeguarded against such exploits through built-in firewall protections.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...