Wednesday, 2 April 2025
29.1 C
Singapore
35.6 C
Thailand
22.1 C
Indonesia
28.5 C
Philippines

Critical security breach in popular WordPress plugin impacts over 200,000 installations

Learn about the critical security flaw in the MW WP Form WordPress plugin affecting over 200,000 sites and how to protect your website effectively.

In a recent revelation by Wordfence, a critical security flaw has been discovered in the MW WP Form plugin, affecting versions up to 5.0.1. This vulnerability allows unauthorised individuals to upload arbitrary files, including potentially harmful PHP backdoors. These files can be executed on the server, presenting a significant security risk.

Understanding the MW WP Form plugin

The MW WP Form plugin is famous for creating forms on WordPress websites. It uses a shortcode builder, making it straightforward for users to design and customise forms with various fields and options. A key feature of this plugin is its file upload capability, facilitated by the [mwform_file name= “file”] shortcode. Unfortunately, this feature has become the focal point of the vulnerability.

The nature of the vulnerability

Termed as an Unauthenticated Arbitrary File Upload Vulnerability, this security flaw allows hackers to upload dangerous files to a website without needing registration or authorisation. Such vulnerabilities can escalate to remote code execution, where the uploaded files are executed on the server, potentially allowing attackers to compromise the website and endanger visitors.

The advisory from Wordfence pointed out a defect in the plugin’s file type check mechanism. While it can detect unsafe file types, a runtime exception allows these files to be uploaded regardless. This oversight enables attackers to upload and activate arbitrary PHP files on the server.

Conditions for a successful attack

This vulnerability poses a significant risk, particularly if the “Saving inquiry data in database” option in the plugin settings is enabled. It has been rated as critically severe, scoring 9.8 out of 10.

Wordfence strongly recommends users of the MW WP Form plugin update to the latest version, 5.0.2, where this issue has been addressed. This advice is especially pertinent for users who have activated the “Saving inquiry data in database” option, as the vulnerability does not require any special permissions to be exploited.

Users should refer to theย full Wordfence advisoryย for comprehensive details and guidance.

Hot this week

Owndays and Huawei launch new titanium smart audio glasses

Owndays and Huawei launch the Eyewear 2 Smart Audio Glasses Titanium Edition, featuring Bluetooth 5.3, 11-hour playback, and a premium frame.

OpenAI set to finalise US$40 billion funding round led by SoftBank

According to Bloomberg, OpenAI is close to finalising a US$40 billion funding round led by SoftBank, which will raise its valuation to US$300 billion.

AI-generated Studio Ghibli art raises fresh copyright concerns

OpenAIโ€™s AI image tool sparks controversy after generating Studio Ghibli-style art, raising new copyright concerns. Legal experts weigh in.

Samsungโ€™s latest vacuum alerts you to calls and texts while you clean

Samsungโ€™s new Bespoke AI Jet Ultra vacuum can alert you to calls and texts while cleaning as the brand expands smart home screens across appliances.

Google Assistant to be phased out on Waze for iPhone

Waze is removing Google Assistant from iPhones due to issues and plans to upgrade with improved voice integration, possibly using Gemini.

Zelle is removing its stand-alone app

Zelle is shutting down its stand-alone app, but you can still use the service through your bankโ€™s app. Hereโ€™s what you need to know.

Apple may launch an AI-powered Health app with a coaching feature next year

Apple may introduce an AI-powered Health app with coaching, food tracking, and fitness guidance in 2026, possibly as a new subscription service.

These robot vacuums are getting smarter with Apple Home support

Appleโ€™s iOS 18.4 update adds Matter support for robot vacuums, enabling control via Apple Home. Roborock, iRobot, and Ecovacs are updating their devices.

Gmail introduces easier encryption for business emails

Google introduces a new encryption model for Gmail, making it easier for businesses to send secure emails without special software or certificates.

Related Articles