CVE-2026-5436 | inc2734 MW WP Form Plugin up to 5.1.1 on WordPress generate_user_file_dirpath Name path traversal
A vulnerability was found in inc2734 MW WP Form Plugin up to 5.1.1 on WordPress. It has been classified as critical. This issue affects the function generate_user_file_dirpath. The manipulation of the argument Name leads to path traversal.
This vulnerability is traded as CVE-2026-5436. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.