Software intelligence
Important: Mw Wp Form appearing in this catalog does not mean your website is affected. Exposure depends on your installed version. How SiteRespond intelligence works
Tracked advisories
10
Latest advisory
9 June 2026
CISA KEV matches
0
In this WordPress feed
WordPress slug
mw-wp-form
Plugin
This catalog lists 10 known advisories affecting Mw Wp Form. The most recent was published on 9 June 2026. If you use this software, compare your installed version against the affected ranges on each advisory and update to a fixed release outside those ranges. SiteRespond Defence checks your actual installed version when the plugin is connected — listing here does not by itself mean your site is vulnerable.
MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 9 June 2026
MW WP Form <= 5.1.3 - Unauthenticated Stored Cross-Site Scripting
May allow attackers to run scripts in visitors' browsers or hijack admin sessions.
Published 1 June 2026
MW WP Form <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Published 13 May 2026
Known Mw Wp Form advisories published by month.
CVE-2026-8853 · Published 9 June 2026
Affected versions: ≤ 5.1.3
CVE-2026-48871 · Published 1 June 2026
Affected versions: ≤ 5.1.3
CVE-2026-6206 · Published 13 May 2026
Affected versions: ≤ 5.1.2
CVE-2026-5436 · Published 8 April 2026
Affected versions: ≤ 5.1.1
CVE-2026-4347 · Published 1 April 2026
Affected versions: ≤ 5.1.0
CVE-2024-24804 · Published 31 January 2024
Affected versions: ≤ 5.0.6
CVE-2023-6559 · Published 15 December 2023
Affected versions: ≤ 5.0.3
CVE-2023-6316 · Published 4 December 2023
Affected versions: ≤ 5.0.1
CVE-2023-46206 · Published 19 October 2023
Affected versions: ≤ 4.4.5
CVE-2023-28409 · Published 8 May 2023
Affected versions: < 4.4.3
SiteRespond Defence matches your installed Mw Wp Form version against this catalog when the Defence plugin is connected to your WordPress site.