PatchSiren

MW WP Form CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review MW WP Form CVE published 2026-08-30

CVE-2026-78364

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T07:17:21.097Z and has not been modified since then. The MW WP Form WordPress plugin before version 5.1.6 has a Stored Cross-Site Scripting vulnerability due to insufficient sanitization and escaping of form settings. This allows users with Editor privileges to potentially perform attacks against [truncated]