Tag
critical
advisory
MW WP Form WordPress Plugin Arbitrary File Move Vulnerability (CVE-2026-4347)
2 rules 2 TTPs 1 CVEThe MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation, allowing unauthenticated attackers to move arbitrary files on the server, potentially leading to remote code execution.
wordpress
file-move
rce
2r
2t
1c
critical
advisory
MW WP Form WordPress Plugin Arbitrary File Move/Read Vulnerability (CVE-2026-5436)
2 rules 2 TTPs 1 CVEThe MW WP Form plugin for WordPress is vulnerable to arbitrary file move/read (CVE-2026-5436) due to insufficient validation of the $name parameter, allowing unauthenticated attackers to move arbitrary files, potentially leading to remote code execution.
MW WP Form plugin
wordpress
file-move
rce
2r
2t
1c