
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4347 is an arbitrary file move vulnerability in the MW WP Form plugin for WordPress, classified as a path traversal flaw (CWE-22). It affects all versions of the plugin up to and including 5.1.0, and was disclosed on April 2, 2026 by Wordfence. The vulnerability allows unauthenticated attackers to move arbitrary files on the server — potentially enabling remote code execution — but only when a file upload field is present in the form and the "Saving inquiry data in database" option is enabled. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Wordfence).
The root cause is insufficient file path validation in two functions: generate_user_filepath (in classes/controllers/class.main.php, line 271) and move_temp_file_to_upload_dir (in classes/models/class.directory.php, line 138). These functions fail to properly sanitize or restrict the destination path when moving temporarily uploaded files, allowing an attacker to supply path traversal sequences that redirect file movement to arbitrary locations on the server. By moving a critical file such as wp-config.php to a web-accessible directory, an attacker can expose database credentials or trigger PHP execution of attacker-controlled content, leading to remote code execution. Exploitation requires two preconditions: a file upload field must be configured in the form, and the "Saving inquiry data in database" option must be enabled (GitHub Advisory, Wordfence).
Successful exploitation allows unauthenticated attackers to move arbitrary files on the server, which can lead to full compromise of the WordPress installation. Moving wp-config.php to a web-accessible path exposes database credentials, while moving attacker-uploaded files to executable locations enables remote code execution with the privileges of the web server process. This can result in data theft, site defacement, installation of malware or backdoors, and potential lateral movement within the hosting environment, affecting all approximately 200,000 active installations of the plugin (Wordfence, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.07–0.14%, placing it in the 34th percentile for exploitation probability within 30 days (GitHub Advisory). The attack complexity is rated High due to the specific configuration requirements (file upload field and database saving option must both be enabled), which limits the exploitable attack surface. Qualys has added detection for this vulnerability (detection ID 531119) (Qualys).
generate_user_filepath) to include path traversal sequences (e.g., ../../) pointing to a target destination outside the intended upload directory.move_temp_file_to_upload_dir function, lacking proper path validation, moves the file to the attacker-specified location — for example, moving a PHP web shell to a web-accessible directory, or relocating wp-config.php to expose credentials.../, ..%2F, ..%5C) in file path parameters; unexpected outbound connections from the web server process.wp-config.php or PHP files in unexpected web-accessible directories; new or modified PHP files in upload directories (e.g., wp-content/uploads/) with web shell characteristics; missing or relocated wp-config.php from the WordPress root.sh, bash, curl, wget) following access to files in upload directories (Wordfence).No patch was available at the time of initial disclosure for versions up to and including 5.1.0; users should check the WordPress plugin repository for an updated version and upgrade immediately when available. As interim mitigations: (1) disable the file upload field in any MW WP Form forms, or disable the "Saving inquiry data in database" option to eliminate the exploitable configuration; (2) temporarily deactivate or remove the plugin if it is not actively needed; (3) deploy WAF rules to detect and block path traversal patterns in form submissions; (4) enforce strict file system permissions to prevent the web server from writing to sensitive directories; (5) monitor server logs and file system for anomalous file movement activity (Wordfence, Sucuri).
Wordfence published a detailed blog post highlighting that approximately 200,000 WordPress sites are affected, characterizing the vulnerability as a significant risk due to the potential for unauthenticated remote code execution (Wordfence). Sucuri included the vulnerability in its April 2026 patch roundup, reinforcing the recommendation to update or disable the plugin (Sucuri). Tech media outlets such as Techlomedia covered the story under headlines emphasizing the site takeover risk, and the vulnerability was picked up by multiple security aggregators and CVE tracking services shortly after disclosure (Techlomedia).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."