Information Exposure Vulnerability in MW WP Form Plugin for WordPress
CVE-2026-6206
5.3MEDIUM
What is CVE-2026-6206?
The MW WP Form plugin for WordPress has a vulnerability allowing unauthorized data access. Specifically, through the _get_post_property_from_querystring() function, insufficient restrictions permit unauthenticated attackers to retrieve information from password-protected, private, or draft posts. This issue affects all versions up to 5.1.2, posing significant risks to sensitive data security.
Affected Version(s)
MW WP Form 0 <= 5.1.2