Junglewise Threat Intelligence

CVE-2026-48871: MW WP Form unauthenticated XSS in WordPress plugin

CVE-2026-48871 · Severity: high · CVSS 7.1 · Published 2026-06-15

Technologies: MW WP Form.

Executive brief

MW WP Form is a popular WordPress plugin used to create and manage custom contact forms. A security flaw allows unauthenticated attackers to inject malicious scripts into the website, which could lead to unauthorized redirects, theft of user session data, or the display of fraudulent content to site visitors. This vulnerability is particularly risky as it can be used in automated mass-exploit campaigns against many websites simultaneously.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the MW WP Form plugin for WordPress due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts or HTML payloads. Exploitation requires a victim (typically a site administrator or visitor) to interact with a malicious link or crafted page. Successful exploitation can lead to session hijacking, unauthorized redirects, or website defacement. The vulnerability is patched in version 5.1.4.

Affected products

  • MW WP Form MW WP Form <= 5.1.3

Timeline

  • 2026-05-15: disclosed: Reported by VanTastic
  • 2026-06-01: advisory: Patchstack published advisory and mitigation rules
  • 2026-06-15: disclosed: CVE published to NVD

References