DFIR Radar[verified]@DFIR_RadarPatch
The tweet alerts that CVE‑2026‑4347, a high‑CVSS vulnerability in the MW WP Form plugin, allows unauthenticated attackers to move arbitrary files (including wp‑config.php), and it recommends updating to version 5.1 to remediate.
Giuseppe Paternicola[verified]@giuseppe_1337Patch
The tweet alerts to CVE‑2026‑4347, a high‑severity RCE in MW WP Form via arbitrary file movement, and urges immediate patching.
Atomic Edge@atomicedgeWAFPoC
The post links to a proof‑of‑concept for CVE-2026-4347 affecting mw‑wp‑form 5.1.0, but it does not provide exploit code, evidence of active exploitation, or patch information.
CVE@CVEnewDisclosure
CVE-2026-4347 exposes the MW WP Form WordPress plugin to arbitrary file moving attacks stemming from inadequate file path validation in the generate_user_filepath function.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert reports CVE-2026-4347, a vulnerability in MW WP Form <=5.1.0 that permits unauthenticated arbitrary file moves via the move_temp_file_to_upload_dir function. No active exploitation, patch, or PoC details are provided.
The Hacker Wire@TheHackerWireDisclosure
The MW WP Form plugin for WordPress is disclosed as vulnerable to arbitrary file moving (CVE‑2026‑4347) due to insufficient path validation, with no PoC, exploit tool, or patch referenced.