PLUGIN SECURITY

Is Mw Wp Form safe?

MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …

What this plugin does

  • Slug: mw-wp-form
  • Author: Webの相談所
  • 200000+ active installs
  • 84/100 rating (23 reviews on wordpress.org)
  • 1921559 all-time downloads
  • On WordPress.org since 2012-12-17

confirmformmailpreviewshortcode

Maintenance status

  • Latest known version: 5.1.4
  • Last updated: 2026-08-26 10:28am GMT
  • Tested up to WordPress: 6.4.10
  • Requires PHP: 8.0+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

11 known CVEs on file for Mw Wp Form.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8853 MW WP Form [mw-wp-form] < 5.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 5.1.4 5.1.4 2026-06-09 ✓ fixed in latest
CVE-2026-48871 MW WP Form [mw-wp-form] < 5.1.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 5.1.4 5.1.4 2026-06-01 ✓ fixed in latest
CVE-2026-6206 MW WP Form [mw-wp-form] < 5.1.3 Authorization Bypass Through User-Controlled Key Medium 5.3 < 5.1.3 5.1.3 2026-05-13 ✓ fixed in latest
CVE-2024-24804 MW WP Form [mw-wp-form] < 5.1.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 5.1.0 5.1.0 2024-01-31 ✓ fixed in latest
CVE-2023-6559 MW WP Form [mw-wp-form] < 5.0.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 5.0.4 5.0.4 2023-12-15 ✓ fixed in latest
CVE-2023-6316 MW WP Form [mw-wp-form] < 5.0.2 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 5.0.2 5.0.2 2023-12-04 ✓ fixed in latest
CVE-2023-46206 MW WP Form [mw-wp-form] < 5.0.0 Missing Authorization Medium 5.3 < 5.0.0 5.0.0 2023-10-19 ✓ fixed in latest
CVE-2023-28408, CVE-2023-28409 MW WP Form [mw-wp-form] < 4.4.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.8 < 4.4.3 4.4.3 2023-05-15 ✓ fixed in latest
+ 6 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
MW WP Form [mw-wp-form] < 4.4.3 Unknown < 4.4.3 4.4.3 2023-05-09 ✓ fixed in latest
CVE-2023-28409 MW WP Form [mw-wp-form] < 4.4.3 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 4.4.3 4.4.3 2023-05-08 ✓ fixed in latest
MW WP Form [mw-wp-form] < 5.1.1 Unknown < 5.1.1 5.1.1 0000-00-00 ✓ fixed in latest
MW WP Form [mw-wp-form] < 5.1.2 High 8.1 < 5.1.2 5.1.2 0000-00-00 ✓ fixed in latest
CVE-2026-4347 MW WP Form < 5.1.1 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir Unknown < 5.1.1 5.1.1 ✓ fixed in latest
CVE-2026-5436 MW WP Form < 5.1.2 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys Unknown < 5.1.2 5.1.2 ✓ fixed in latest

How to fix it

Keep Mw Wp Form updated — 5.1.4 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.