CVE-2026-4347: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-4347 is an arbitrary file move vulnerability in the MW WP Form plugin for WordPress, classified as a path traversal flaw (CWE-22). It affects all versions of the plugin up to and including 5.1.0, and was disclosed on April 2, 2026 by Wordfence. The vulnerability allows unauthenticated attackers to move arbitrary files on the server — potentially enabling remote code execution — but only when a file upload field is present in the form and the "Saving inquiry data in database" option is enabled. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, Wordfence).

Technical details

The root cause is insufficient file path validation in two functions: generate_user_filepath (in classes/controllers/class.main.php, line 271) and move_temp_file_to_upload_dir (in classes/models/class.directory.php, line 138). These functions fail to properly sanitize or restrict the destination path when moving temporarily uploaded files, allowing an attacker to supply path traversal sequences that redirect file movement to arbitrary locations on the server. By moving a critical file such as wp-config.php to a web-accessible directory, an attacker can expose database credentials or trigger PHP execution of attacker-controlled content, leading to remote code execution. Exploitation requires two preconditions: a file upload field must be configured in the form, and the "Saving inquiry data in database" option must be enabled (GitHub Advisory, Wordfence).

Impact

Successful exploitation allows unauthenticated attackers to move arbitrary files on the server, which can lead to full compromise of the WordPress installation. Moving wp-config.php to a web-accessible path exposes database credentials, while moving attacker-uploaded files to executable locations enables remote code execution with the privileges of the web server process. This can result in data theft, site defacement, installation of malware or backdoors, and potential lateral movement within the hosting environment, affecting all approximately 200,000 active installations of the plugin (Wordfence, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Wordfence). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.07–0.14%, placing it in the 34th percentile for exploitation probability within 30 days (GitHub Advisory). The attack complexity is rated High due to the specific configuration requirements (file upload field and database saving option must both be enabled), which limits the exploitable attack surface. Qualys has added detection for this vulnerability (detection ID 531119) (Qualys).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the MW WP Form plugin (versions ≤ 5.1.0) via passive scanning tools (e.g., WPScan, Shodan) or by inspecting page source for plugin-specific assets. Confirm the target form has a file upload field and that the "Saving inquiry data in database" option is enabled.
  2. Upload a temporary file: Submit a multipart form POST request to the vulnerable MW WP Form endpoint, including a file in the upload field. The plugin temporarily stores the file on the server.
  3. Craft a path traversal payload: In the subsequent form submission or file-handling request, manipulate the file path parameter (processed by generate_user_filepath) to include path traversal sequences (e.g., ../../) pointing to a target destination outside the intended upload directory.
  4. Trigger arbitrary file move: The move_temp_file_to_upload_dir function, lacking proper path validation, moves the file to the attacker-specified location — for example, moving a PHP web shell to a web-accessible directory, or relocating wp-config.php to expose credentials.
  5. Achieve remote code execution: Access the moved PHP file via the browser to execute arbitrary commands on the server with web server process privileges, enabling full site takeover (GitHub Advisory, Wordfence).

Indicators of compromise

  • Network: Unusual multipart POST requests to MW WP Form endpoints containing path traversal sequences (../, ..%2F, ..%5C) in file path parameters; unexpected outbound connections from the web server process.
  • File System: Presence of wp-config.php or PHP files in unexpected web-accessible directories; new or modified PHP files in upload directories (e.g., wp-content/uploads/) with web shell characteristics; missing or relocated wp-config.php from the WordPress root.
  • Logs: Web server access logs showing POST requests to MW WP Form processing endpoints with encoded path traversal strings in parameters; HTTP 200 responses to newly created PHP files in upload directories.
  • Process: Unexpected child processes spawned by the web server (e.g., sh, bash, curl, wget) following access to files in upload directories (Wordfence).

Mitigation and workarounds

No patch was available at the time of initial disclosure for versions up to and including 5.1.0; users should check the WordPress plugin repository for an updated version and upgrade immediately when available. As interim mitigations: (1) disable the file upload field in any MW WP Form forms, or disable the "Saving inquiry data in database" option to eliminate the exploitable configuration; (2) temporarily deactivate or remove the plugin if it is not actively needed; (3) deploy WAF rules to detect and block path traversal patterns in form submissions; (4) enforce strict file system permissions to prevent the web server from writing to sensitive directories; (5) monitor server logs and file system for anomalous file movement activity (Wordfence, Sucuri).

Community reactions

Wordfence published a detailed blog post highlighting that approximately 200,000 WordPress sites are affected, characterizing the vulnerability as a significant risk due to the potential for unauthenticated remote code execution (Wordfence). Sucuri included the vulnerability in its April 2026 patch roundup, reinforcing the recommendation to update or disable the plugin (Sucuri). Tech media outlets such as Techlomedia covered the story under headlines emphasizing the site takeover risk, and the vulnerability was picked up by multiple security aggregators and CVE tracking services shortly after disclosure (Techlomedia).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management