Unauthenticated Cross Site Scripting Vulnerability in MW WP Form Plugin
CVE-2026-48871
7.1HIGH
What is CVE-2026-48871?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in the MW WP Form plugin for WordPress, affecting versions up to 5.1.3. This flaw enables attackers to inject malicious scripts into web pages viewed by users, potentially leading to session hijacking, data theft, or other malicious actions. It is crucial for site administrators to patch their installations to mitigate the risks associated with this vulnerability.
Affected Version(s)
MW WP Form <= 5.1.3