CVE-2026-4347Disclosure

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_dir' function in all versions up to, and including, 5.1.0. This makes it possible for unauthenticated attackers to move arbitrary files on the server, which can easily lead to remote code execution when the right file is moved (such as wp-config.php). The vulnerability is only exploitable if a file upload field is added to the form and the “Saving inquiry data in database” option is enabled.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-02); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-04-02: 3Mentions · 2026-04-03: 1Mentions · 2026-04-08: 1Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-08: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-02: 3Technical Details · 2026-04-03: 1Technical Details · 2026-04-27: 104-0204-0304-0804-27
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
PoC
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-023
Disclosure3
2026-04-031
Patch1
2026-04-081
PoC1
2026-04-271
Patch1
Full discourse6 posts
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-4347 (CVSS 8.1) in MW WP Form plugin affects 200K+ WordPress sites. Unauthenticated attackers can move arbitrary files including wp-config.php, enabling site takeover. Update to v5.1. #DFIR_Radar https://t.co/V00EPAXTWc

    Post summary

    The tweet alerts that CVE‑2026‑4347, a high‑CVSS vulnerability in the MW WP Form plugin, allows unauthenticated attackers to move arbitrary files (including wp‑config.php), and it recommends updating to version 5.1 to remediate.

    10010130
    1.1K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-4347 (CVSS 8.1) - MW WP Form plugin for WordPress vulnerable to arbitrary file moving → RCE. Affects all versions ≤5.1.0. Unauthenticated exploit possible when file upload enabled. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/N0cZ6iiW6K

    Post summary

    The tweet alerts to CVE‑2026‑4347, a high‑severity RCE in MW WP Form via arbitrary file movement, and urges immediate patching.

    0000193
    27 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4347-mw-wp-form-version-5-1-0-high-vulnerability-proof-of-concept CVE-2026-4347 #WordPress plugin #vulnerability mw-wp-form #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The post links to a proof‑of‑concept for CVE-2026-4347 affecting mw‑wp‑form 5.1.0, but it does not provide exploit code, evidence of active exploitation, or patch information.

    0000056
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4347 The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'm… https://www.cve.org/CVERecord?id=CVE-2026-4347

    Post summary

    CVE-2026-4347 exposes the MW WP Form WordPress plugin to arbitrary file moving attacks stemming from inadequate file path validation in the generate_user_filepath function.

    00000132
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4347 - MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir Intel Report: https://ift.tt/tqCb2MO

    Post summary

    The alert reports CVE-2026-4347, a vulnerability in MW WP Form <=5.1.0 that permits unauthenticated arbitrary file moves via the move_temp_file_to_upload_dir function. No active exploitation, patch, or PoC details are provided.

    0000051
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4347 - High The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the 'move_temp_file_to_upload_... https://www.thehackerwire.com/vulnerability/CVE-2026-4347/ https://t.co/TEo8FWIDGD

    Post summary

    The MW WP Form plugin for WordPress is disclosed as vulnerable to arbitrary file moving (CVE‑2026‑4347) due to insufficient path validation, with no PoC, exploit tool, or patch referenced.

    0000073
    163 followersView on X

Explore more