Tag
The MW WP Form WordPress plugin is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient sanitization of the 'post_id' parameter, enabling unauthenticated attackers to bypass CSRF protections and execute arbitrary scripts in victim sessions.