Friday, 22 November 2024
26.1 C
Singapore

Critical security breach in popular WordPress plugin impacts over 200,000 installations

Learn about the critical security flaw in the MW WP Form WordPress plugin affecting over 200,000 sites and how to protect your website effectively.

In a recent revelation by Wordfence, a critical security flaw has been discovered in the MW WP Form plugin, affecting versions up to 5.0.1. This vulnerability allows unauthorised individuals to upload arbitrary files, including potentially harmful PHP backdoors. These files can be executed on the server, presenting a significant security risk.

Understanding the MW WP Form plugin

The MW WP Form plugin is famous for creating forms on websites. It uses a shortcode builder, making it straightforward for users to design and customise forms with various fields and options. A key feature of this plugin is its file upload capability, facilitated by the [mwform_file name= “file”] shortcode. Unfortunately, this feature has become the focal point of the vulnerability.

The nature of the vulnerability

Termed as an Unauthenticated Arbitrary File Upload Vulnerability, this security flaw allows hackers to upload dangerous files to a without needing registration or authorisation. Such vulnerabilities can escalate to remote code execution, where the uploaded files are executed on the server, potentially allowing attackers to compromise the website and endanger visitors.

The advisory from Wordfence pointed out a defect in the plugin’s file type check mechanism. While it can detect unsafe file types, a runtime exception allows these files to be uploaded regardless. This oversight enables attackers to upload and activate arbitrary PHP files on the server.

Conditions for a successful attack

This vulnerability poses a significant risk, particularly if the “Saving inquiry data in database” option in the plugin settings is enabled. It has been rated as critically severe, scoring 9.8 out of 10.

Wordfence strongly recommends users of the MW WP Form plugin update to the latest version, 5.0.2, where this issue has been addressed. This advice is especially pertinent for users who have activated the “Saving inquiry data in database” option, as the vulnerability does not require any special permissions to be exploited.

Users should refer to the full Wordfence advisory for comprehensive details and guidance.

Hot this week

FPT and Sitecore launch ON.E, an AI-powered e-commerce accelerator

FPT and Sitecore launch ON.E, an AI-powered e-commerce accelerator aimed at transforming digital commerce for retailers globally.

US plans historic crackdown on Google, may force sale of Chrome browser

The US may force Google to sell Chrome in a landmark antitrust case, targeting its dominance in search, AI, and mobile systems to promote competition.

Xiaomi’s Q3 2024 revenue exceeds expectations, driven by strong growth across key sectors

Xiaomi's Q3 2024 revenue reaches a record high, with growth across smartphones, IoT, and EVs, and continued investment in cutting-edge technology.

Ohio man guilty of Bitcoin laundering to forfeit over US$400 million in assets

Ohio man Larry Dean Harmon was sentenced to 3 years for Bitcoin laundering and forfeiting US$400M+ in assets, highlighting crypto mixer misuse.

Valve marks 20 years of Half-Life 2 with an exciting anniversary update

Celebrate Half-Life 2's 20th anniversary with Valve's big update, featuring expansions, a documentary, and accessible gameplay on Steam until November 18.

UGREEN Surge Protector Power Strip review: Fast charging meets smart safety

The UGREEN Surge Protector Power Strip offers fast charging, 10-device support, and surge protection but faces durability concerns.

Microsoft’s AI agents in Microsoft 365 to handle your mundane tasks

Boost productivity with Microsoft 365's new AI agents, handling tasks in SharePoint, Teams, and Planner for better efficiency and collaboration.

New features in GPT-4o enhance creativity and efficiency

GPT-4o enhances creative writing with improved speed, capabilities, and cost-efficiency, offering tailored and natural responses for users.

The Windows 11 24H2 update continues to cause problems

Windows 11 24H2 update causes time zone bugs, audio glitches, and sync issues; Microsoft promises fixes in the next update.

Related Articles

Popular Categories