WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in MW WP Form

MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …

11Reported vulnerabilities
9.8Highest CVSS score
5.1.4Latest version
200,000+Active installs

What to do now

Update MW WP Form to 5.1.6 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: May 24, 2026 / Tested up to WordPress: 6.4.10 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2023-6316 Critical 9.8 1.4% 5.0.1 and earlier 5.0.2 January 11, 2024
CVE-2023-6559 Critical 9.8 1.3% Before 5.0.4 5.0.4 December 16, 2023
CVE-2026-5436 High 8.1 1.1% 0 to 5.1.1 (inclusive) 5.1.2 April 8, 2026
CVE-2026-4347 High 8.1 1.3% 0 to 5.1.0 (inclusive) 5.1.1 April 2, 2026
CVE-2026-48871 High 7.2 0.2% 5.1.3 and earlier 5.1.4 June 1, 2026
CVE-2023-28409 Medium 5.3 1.2% Before 4.4.3 4.4.3 May 8, 2023
CVE-2024-24804 Medium 5.5 0.3% 5.0.6 and earlier 5.1.0 January 31, 2024
CVE-2026-6206 Medium 5.3 0.4% 0 to 5.1.2 (inclusive) 5.1.3 May 14, 2026
CVE-2023-46206 Medium 5.3 0.4% 4.4.5 and earlier 5.0.0 October 19, 2023
CVE-2026-8853 Medium 4.4 0.3% 0 to 5.1.3 (inclusive) 5.1.4 June 10, 2026
CVE-2026-78364 Medium 4.4 0.1% Before 5.1.6 5.1.6 August 28, 2026

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.