Executive brief
The MW WP Form plugin for WordPress, which is used to create and manage contact forms, contains a security flaw that allows authorized users with editor-level access to inject malicious scripts into the website. These scripts execute automatically when other users visit the affected pages, potentially leading to unauthorized actions or data theft. This issue occurs because the plugin does not properly clean certain text fields before saving them to the database.
Technical details
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'memo' parameter in versions up to and including 5.1.3. The vulnerability exists because the plugin uses update_post_meta() to store the 'memo' value instead of wp_insert_post(), which bypasses WordPress's built-in kses and unfiltered_html security filters. An authenticated attacker with editor-level permissions or higher can inject arbitrary web scripts by breaking out of the textarea element using closing tags. These scripts then execute in the context of any user accessing the contact data detail page. The issue has been addressed in version 5.1.4.
Affected products
- MW WP Form MW WP Form Up to and including 5.1.3
Timeline
- 2026-06-10: advisory: NVD published the vulnerability details.
- 2026-06-10: disclosed: Wordfence published the vulnerability report.
- 2026-06-10: patched: Version 5.1.4 released to address the vulnerability.
References
- https://plugins.trac.wordpress.org/browser/mw-wp-form/tags/5.1.0/classes/controllers/class.contact-data.php
- https://plugins.trac.wordpress.org/browser/mw-wp-form/tags/5.1.0/templates/contact-data/detail.php
- https://plugins.trac.wordpress.org/browser/mw-wp-form/tags/5.1.3/classes/controllers/class.contact-data.php
- https://plugins.trac.wordpress.org/browser/mw-wp-form/tags/5.1.3/templates/contact-data/detail.php
- https://plugins.trac.wordpress.org/changeset?old_path=mw-wp-form/tags/5.1.3&new_path=mw-wp-form/tags/5.1.4
- https://www.wordfence.com/threat-intel/vulnerabilities/id/2a6dfdec-c1c6-4300-ab0a-9fd1c550d09f?source=cve