Arbitrary File Move in MW WP Form for WordPress
CVE-2026-4347 is an arbitrary file moving vulnerability in the MW WP Form plugin for WordPress affecting all versions up to and including 5.1.0. The issue is caused by insufficient file path validation in the generate_user_filepath and move_temp_file_to_upload_dir functions. An unauthenticated attacker can abuse the vulnerable file-handling logic to cause arbitrary files on the server to be moved. The provided context specifically notes that moving a sensitive file such as wp-config.php can turn the issue into remote code execution. The flaw is only reachable in deployments where a form includes a file upload field and the plugin option for saving inquiry data in the database is enabled.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related earlier MW WP Form vulnerability whose fix in version 5.1.1 was insufficient and could be bypassed through an alternative code path, leading to the later CVE-2026-5436 issue.
An arbitrary file moving vulnerability in the MW WP Form plugin for WordPress caused by insufficient file path validation, affecting versions up to and including 5.1.0, and potentially leading to remote code execution.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.