Impact
The MW WP Form plugin before 5.1.6 fails to sanitise and escape certain form settings before rendering them in the admin dashboard. This flaw permits a user with Editor privileges to inject malicious JavaScript into those settings, which is stored and later executed when an administrator or other high‑privilege user views the settings page. The stored XSS could lead to session hijacking, defacement, or arbitrary code execution in the context of the privileged user.
Affected Systems
The vulnerability affects any WordPress site that has the MW WP Form plugin installed with a version earlier than 5.1.6. The only vendor detail provided is MW WP Form, and no additional version ranges are specified beyond "<5.1.6".
Risk and Exploitability
The EPSS score of < 1% indicates a very low probability of exploitation, and the CVSS score of 3.5 reflects low severity. However, because the flaw enables stored cross‑site scripting that is executed in an administrator’s context, the impact can be significant for sites where Editor users have the ability to modify the plugin’s settings. The attack requires the attacker to be logged in with at least Editor privileges and to access the admin dashboard; no external network trigger is needed. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment