Description
WordPress Plugin MW WP Form is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin MW WP Form version 4.4.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.4.3 or latest
References
Related Vulnerabilities
WordPress Plugin SendPress Newsletters Unspecified Vulnerability (1.7.6.11)
WordPress Plugin Ultimate Addons for Beaver Builder Security Bypass (1.24.0)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2016-1546)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-2890)