Critical severity9.8NVD Advisory· Published May 23, 2023· Updated Jun 17, 2026
CVE-2023-28408
CVE-2023-28408
Description
Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mw_wp_form_project:mw_wp_form:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:mw_wp_form_project:mw_wp_form:*:*:*:*:*:wordpress:*:*range: <=4.4.2
- (no CPE)range: versions v4.4.2 and earlier
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN01093915/nvdThird Party Advisory
- plugins.2inc.org/mw-wp-form/blog/2023/05/08/752/nvdVendor Advisory
News mentions
0No linked articles in our index yet.