Junglewise Threat Intelligence

CVE-2026-78364: MW WP Form Stored XSS in admin form settings

CVE-2026-78364 · Severity: low · CVSS 3.5 · Published 2026-08-30

Technologies: MW WP Form.

Executive brief

The MW WP Form WordPress plugin fails to properly sanitize and escape form configuration settings before displaying them in the admin dashboard. An attacker with Editor-level access can inject malicious JavaScript code into form settings, which executes when administrators view the saved form submissions. This allows unauthorized code execution in the admin's browser session, potentially leading to account compromise or data theft.

Technical details

This is a Stored Cross-Site Scripting (XSS) vulnerability in the MW WP Form WordPress plugin versions before 5.1.6. The vulnerability exists in the form settings storage mechanism, specifically in the "Admin Email Options" and inquiry data list display. An authenticated user with Editor or higher role can inject malicious JavaScript via form configuration fields (the "To" email address and column header templates), which is stored in the database without proper sanitization. When an administrator views the inquiry data list on the dashboard, the unsanitized settings are rendered as HTML, causing the injected script to execute in the admin's session. The vulnerability requires admin interaction (viewing the entries list) and allows arbitrary JavaScript execution within the administrator's authenticated context. A patch is available in version 5.1.6 and later.

Affected products

  • MW WP Form MW WP Form before 5.1.6

Timeline

  • 2026-08-28: disclosed
  • 2026-08-30: patched: Fixed in version 5.1.6

References