{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mw-wp-form--5.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mw_wp_form_project:mw_wp_form:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96567"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MW WP Form (\u003c= 5.1.7)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-96567"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe MW WP Form plugin for WordPress, in versions 5.1.7 and earlier, contains a critical input sanitization vulnerability. Attackers can leverage this flaw to perform Stored Cross-Site Scripting (XSS) by manipulating the 'post_id' parameter during form processing. The vulnerability is compounded by an insecure CSRF protection mechanism (MW_WP_Form_Csrf), which relies on a double-submit cookie that can be acquired by any unauthenticated visitor who loads the public-facing form page. Because the plugin fails to properly sanitize input or escape output, malicious actors can inject arbitrary JavaScript payloads into the WordPress database. These payloads execute in the browsers of users - including administrators - who view the affected pages or form submissions, potentially leading to unauthorized actions, session hijacking, or site defacement. This issue highlights the danger of predictable or bypassable CSRF tokens when combined with inadequate input handling.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker loads a public webpage containing a form managed by the MW WP Form plugin.\u003c/li\u003e\n\u003cli\u003eThe application serves the form and issues a double-submit CSRF cookie (MW_WP_Form_Csrf) to the browser.\u003c/li\u003e\n\u003cli\u003eThe attacker retrieves the valid CSRF token/cookie pair from the initial page load.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request targeting the form submission endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker includes a cross-site scripting payload within the 'post_id' parameter.\u003c/li\u003e\n\u003cli\u003eThe application accepts the POST request, validating the CSRF cookie, and saves the malicious 'post_id' to the underlying database without sanitization.\u003c/li\u003e\n\u003cli\u003eA victim user, such as an administrator, accesses the administrative interface or a page displaying the form submission data.\u003c/li\u003e\n\u003cli\u003eThe stored JavaScript payload executes in the victim's browser context, enabling further malicious activity.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of any user who accesses the compromised form submission pages. This may result in total site compromise if an administrative account views the malicious payload, enabling account takeover, unauthorized creation of admin users, or malicious modifications to site content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify all WordPress instances running MW WP Form versions 5.1.7 or older.\u003c/li\u003e\n\u003cli\u003eUpdate the MW WP Form plugin to the latest secure version addressing CVE-2026-96567.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block POST requests containing suspicious characters (e.g., \u0026lt;script\u0026gt;, javascript:, onload=) in the 'post_id' parameter.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous POST requests to form submission endpoints originating from unknown or non-customer IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T10:23:25Z","date_published":"2026-10-02T10:23:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mw-wp-form-xss/","summary":"The MW WP Form WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of the 'post_id' parameter, enabling unauthenticated attackers to bypass CSRF protections and execute arbitrary scripts in victim sessions.","title":"Stored XSS in MW WP Form WordPress Plugin via post_id Parameter","url":"https://feed.craftedsignal.io/briefs/2026-10-mw-wp-form-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - MW WP Form (\u003c= 5.1.7)","version":"https://jsonfeed.org/version/1.1"}