high · CVSS v3 7.2 · EPSS 0.00259
CVE-2026-96567
The MW WP Form plugin for WordPress is vulnerable to stored XSS via the post_id parameter. Unauthenticated attackers can inject scripts that
Overview
The MW WP Form plugin for WordPress is vulnerable to stored XSS via the post_id parameter. Unauthenticated attackers can inject scripts that run for any user viewing the page. This allows malicious code execution on site visitors.
Description
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The CSRF gate protecting form submission (MW_WP_Form_Csrf) is bypassable by any unauthenticated visitor who first loads the public form page to obtain a valid double-submit cookie, leaving no effective barrier to storing malicious payloads.
Impact
Confidentiality: injected scripts may exfiltrate user data. Integrity: malicious scripts can alter page content. Availability: not directly affected. Defenders: site administrators and users are impacted.
Remediation
Update MW WP Form to version 5.1.8 or later. If update is not possible, disable the plugin or block the post_id parameter using a web application firewall. Ensure proper input sanitization and output escaping. Use security plugins to detect and block XSS payloads.
Risk context
High severity (CVSS 7.2) but low EPSS (0.00259) indicates a low likelihood of exploitation. Defenders should patch promptly to mitigate potential XSS attacks.
Affected products
- WordPress
- MW WP Form
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00259