WordPress Plugin MW WP Form Arbitrary File Deletion - CVE-2023-6559 - Vulnerability Database

WordPress Plugin MW WP Form Arbitrary File Deletion - CVE-2023-6559

High
Reference: CVE-2023-6559
Title: WordPress Plugin MW WP Form Arbitrary File Deletion
Overview:

WordPress Plugin MW WP Form is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. An attacker can exploit this vulnerability to delete arbitrary files in the context of the webserver process. WordPress Plugin MW WP Form version 5.0.3 is vulnerable prior versions may also be affected.