Impact
The MW WP Form plugin before version 5.1.6 fails to sanitise and escape some form settings when rendering them in the admin dashboard. This flaw allows a user with Editor privileges to inject script that is stored and later executed when an Administrator or other high‑privilege user views the settings page. The stored XSS could lead to session hijacking, defacement, or execution of arbitrary JavaScript in the context of an admin user.
Affected Systems
The vulnerability affects the MW WP Form WordPress plugin running on any WordPress site that has an installation of MW WP Form version earlier than 5.1.6. The plugin is provided by a vendor identified only as MW WP Form, and no further version detail beyond <5.1.6 is given.
Risk and Exploitability
No EPSS score is available; the vulnerability has not been listed in CISA KEV, which suggests a lower but still meaningful exploitation likelihood. The CVSS score is not provided, but stored XSS scores generally rate high. Attackers can exploit this vulnerability via the admin dashboard when logged in as an Editor or higher role; no external network trigger is required. The risk is higher for sites where Editors are granted many capabilities or where multiple users have access to the plugin settings. The local nature of the attack does not require remote network access but depends on having sufficient role privileges.
OpenCVE Enrichment