Vulnerabilities > WEB Soudan

DATE CVE VULNERABILITY TITLE RISK
2024-02-10 CVE-2024-24804 Cross-site Scripting vulnerability in Web-Soudan MW WP Form
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in websoudan MW WP Form allows Stored XSS.This issue affects MW WP Form: from n/a through 5.0.6.
network
low complexity
web-soudan CWE-79
5.4
2023-12-16 CVE-2023-6559 Path Traversal vulnerability in Web-Soudan MW WP Form
The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3.
network
low complexity
web-soudan CWE-22
critical
9.8