All verified exploits

CVE-2026-4347 Arbitrary File Move via Form Plugin Path Traversal

Deterministic high WordPress Added cve-verified-cve-2026-4347

Detects MW WP Form plugin versions 5.1.0 and below where the generate_user_filepath() function fails to validate absolute paths. An unauthenticated attacker can move arbitrary server files (like wp-config.php) to the uploads directory via a form with a file upload field, potentially causing full takeover. Update to MW WP Form 5.1.1 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-4347?

Scan your domain free