Detects MW WP Form plugin versions 5.1.0 and below where the generate_user_filepath() function fails to validate absolute paths. An unauthenticated attacker can move arbitrary server files (like wp-config.php) to the uploads directory via a form with a file upload field, potentially causing full takeover. Update to MW WP Form 5.1.1 or later.
Is your app exploitable through CVE-2026-4347?
Scan your domain free