Description
WordPress Plugin MW WP Form is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin MW WP Form version 5.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.0.4 or latest
References
Related Vulnerabilities
WordPress Plugin AB Press Optimizer Multiple Cross-Site Scripting Vulnerabilities (1.1.1)
Internet Information Services Other Vulnerability (CVE-2002-1181)
Magento Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3458)
Plone CMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-5500)
Jenkins Incorrect Authorization Vulnerability (CVE-2021-21670)