CVE-2026-4347 identifies an arbitrary file moving vulnerability in the MW WP Form plugin for WordPress, affecting all versions up to 5.1.0. This flaw, caused by insufficient file path validation, allows unauthenticated attackers to move arbitrary files on the server, potentially leading to remote code execution if specific form configurations are enabled. Rated 8.1 High severity (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), its exploitation requires high attack complexity but can result in complete system compromise. While no public exploits or active exploitation are currently known, its presence on a "Hot List" indicates its significance and potential for future exploitation, urging immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Inc2734 | MW WP Form | >= 0, <= 5.1.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.