rootpwn

high · CVSS v3 7.2 · EPSS 0.00259

CVE-2026-96567

The MW WP Form plugin for WordPress is vulnerable to stored XSS via the post_id parameter. Unauthenticated attackers can inject scripts that

Overview

The MW WP Form plugin for WordPress is vulnerable to stored XSS via the post_id parameter. Unauthenticated attackers can inject scripts that run for any user viewing the page. This allows malicious code execution on site visitors.

Description

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The CSRF gate protecting form submission (MW_WP_Form_Csrf) is bypassable by any unauthenticated visitor who first loads the public form page to obtain a valid double-submit cookie, leaving no effective barrier to storing malicious payloads.

Impact

Confidentiality: injected scripts may exfiltrate user data. Integrity: malicious scripts can alter page content. Availability: not directly affected. Defenders: site administrators and users are impacted.

Remediation

Update MW WP Form to version 5.1.8 or later. If update is not possible, disable the plugin or block the post_id parameter using a web application firewall. Ensure proper input sanitization and output escaping. Use security plugins to detect and block XSS payloads.

Risk context

High severity (CVSS 7.2) but low EPSS (0.00259) indicates a low likelihood of exploitation. Defenders should patch promptly to mitigate potential XSS attacks.

Affected products

  • WordPress
  • MW WP Form

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00259

XSS Stored XSS WordPress MW WP Form CSRF bypass High severity Web application

← All CVEs