Medium 5.3
2026-05-14< 5.1.3
CVE-2026-6206
Minimum safe version
5.1.3
Update to 5.1.3 or later to address 11 fixable vulnerabilities
CVE-2026-6206
MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys
WordPress MW WP Form Plugin <= 5.1.0 is vulnerable to a high priority Directory Traversal
CVE-2024-24804
WordPress MW WP Form Plugin <= 5.0.3 is vulnerable to Arbitrary File Deletion
CVE-2023-6316
CVE-2023-46206
CVE-2023-28408
CVE-2023-28409
WordPress MW WP Form Plugin < 4.4.3 is vulnerable to Directory Traversal
MW WP Form <= 4.4.2 - Directory Traversal via _file_upload