Mw Wp Form Project maintains a WordPress form-builder plugin with a focused vulnerability footprint centered on file-handling and path-manipulation weaknesses, including unrestricted file uploads and path-traversal conditions that are characteristic of web-application input-processing challenges. Current severity, exploitation activity, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mw Wp Form Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28409CRITICAL Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file. | May 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-28408CRITICAL Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) conditi | May 23, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-6316CRITICAL The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function in versions up to, and in | Jan 11, 2024 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mw Wp Form Project.
Media articles that mention a CVE ID that affects a product developed by Mw Wp Form Project — matched by CVE ID, not by vendor name.