Sceawere
Vulnerability Detail
CVE-2026-96567UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MW WP Form Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 15h ago
- Vendor
- websoudan
- Product
- MW WP Form
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_id' parameter in all versions up to, and including, 5.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The CSRF gate protecting form submission (MW_WP_Form_Csrf) is bypassable by any unauthenticated visitor who first loads the public form page to obtain a valid double-submit cookie, leaving no effective barrier to storing malicious payloads.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-02T08:17:04.310Z",
"pubdate": "2026-10-02T08:17:04.310Z",
"executiveSummary": "The MW WP Form plugin for WordPress, in versions up to and including 5.1.7, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw arises from inadequate input sanitization and insufficient output escaping of the 'post_id' parameter.\nThe vulnerability is critical as it allows unauthenticated attackers to inject and execute arbitrary JavaScript within the context of the victim's browser. Successful exploitation is facilitated by a bypassable CSRF protection mechanism, specifically the MW_WP_Form_Csrf component, which fails to prevent malicious requests from unauthenticated users.\nThe primary risk involves the injection of persistent malicious scripts into WordPress pages. When a user or administrator accesses an affected page, the malicious code executes, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive data. Because the exploit does not require prior authentication and can circumvent CSRF protections, it poses a significant threat to the integrity and security of the WordPress installation.",
"technicalDetails": "The vulnerability stems from the improper handling of the 'post_id' parameter within the MW WP Form plugin. The application fails to sanitize this user-supplied input before processing it and lacks necessary output escaping when rendering the data. This deficiency enables the injection of malicious web scripts into the plugin's storage backend, which are then persisted and rendered on the front end.\nA key component of this exploit is the bypassable CSRF protection mechanism (MW_WP_Form_Csrf). The plugin relies on a double-submit cookie to validate form submissions; however, this mechanism is flawed as any unauthenticated attacker can retrieve a valid CSRF cookie simply by loading the public form page. By obtaining this token, the attacker can successfully bypass the gate intended to prevent unauthorized or automated form submissions.\nThe attack flow proceeds as follows: First, the attacker visits the public page where the MW WP Form is rendered, triggering the server to issue a valid CSRF cookie. Second, the attacker crafts a malicious request containing a crafted payload within the 'post_id' parameter, appending the previously obtained CSRF token to pass the validation check. Third, the plugin, failing to properly sanitize the 'post_id' input, stores the malicious script directly into the database.\nOnce the payload is stored, the final stage occurs when a legitimate user or administrator navigates to the compromised page. The browser parses the stored script as part of the page content, executing it within the security context of the site. The impact is significant: since the script executes under the victim's session, the attacker can perform actions on behalf of the user, steal session cookies, capture sensitive data displayed on the page, or redirect the user to malicious domains.\nThis vulnerability affects all versions of MW WP Form up to and including 5.1.7. It does not require any specific privilege level or authentication, as the entire entry point is exposed to the public-facing side of the application via the standard form submission process."
}