Wednesday, 15 October 2025
30.8 C
Singapore
31.4 C
Thailand
28.5 C
Indonesia
28.1 C
Philippines

Critical security breach in popular WordPress plugin impacts over 200,000 installations

Learn about the critical security flaw in the MW WP Form WordPress plugin affecting over 200,000 sites and how to protect your website effectively.

In a recent revelation by Wordfence, a critical security flaw has been discovered in the MW WP Form plugin, affecting versions up to 5.0.1. This vulnerability allows unauthorised individuals to upload arbitrary files, including potentially harmful PHP backdoors. These files can be executed on the server, presenting a significant security risk.

Understanding the MW WP Form plugin

The MW WP Form plugin is famous for creating forms on WordPress websites. It uses a shortcode builder, making it straightforward for users to design and customise forms with various fields and options. A key feature of this plugin is its file upload capability, facilitated by the [mwform_file name= “file”] shortcode. Unfortunately, this feature has become the focal point of the vulnerability.

The nature of the vulnerability

Termed as an Unauthenticated Arbitrary File Upload Vulnerability, this security flaw allows hackers to upload dangerous files to a website without needing registration or authorisation. Such vulnerabilities can escalate to remote code execution, where the uploaded files are executed on the server, potentially allowing attackers to compromise the website and endanger visitors.

The advisory from Wordfence pointed out a defect in the plugin’s file type check mechanism. While it can detect unsafe file types, a runtime exception allows these files to be uploaded regardless. This oversight enables attackers to upload and activate arbitrary PHP files on the server.

Conditions for a successful attack

This vulnerability poses a significant risk, particularly if the “Saving inquiry data in database” option in the plugin settings is enabled. It has been rated as critically severe, scoring 9.8 out of 10.

Wordfence strongly recommends users of the MW WP Form plugin update to the latest version, 5.0.2, where this issue has been addressed. This advice is especially pertinent for users who have activated the “Saving inquiry data in database” option, as the vulnerability does not require any special permissions to be exploited.

Users should refer to the full Wordfence advisory for comprehensive details and guidance.

Hot this week

Infor launches industry-focused AI agents to transform enterprise operations

Infor launches industry-specific AI agents, new cloud migration tools, and enhanced process mining to transform enterprise workflows and accelerate automation.

ASUS launches Ascent GX10 personal AI supercomputer

ASUS launches the Ascent GX10 personal AI supercomputer, delivering petaflop-scale performance in a compact desktop form.

Microsoft expands Copilot on Windows with Office document creation and Gmail integration

Microsoft updates Copilot on Windows with Office document creation, Gmail integration, and new AI productivity features.

Facebook reintroduces job listings with a focus on local work

Facebook is reintroducing job listings for local, entry-level, and trade work in the US, accessible through Marketplace and groups.

NVIDIA Spectrum-X Ethernet switches power next-generation AI data centres for Meta and Oracle

Meta and Oracle adopt NVIDIA Spectrum-X Ethernet switches to boost AI data centre performance and accelerate giga-scale model training.

Salesforce launches Agentforce 360 to power the era of the agentic enterprise

Salesforce launches Agentforce 360, an AI platform designed to boost human potential and transform how businesses work in the age of AI.

Singlife partners with Salesforce to launch AI agent for customer service

Singlife partners with Salesforce to launch an AI agent that enhances customer service response times and efficiency.

ASUS launches Ascent GX10 personal AI supercomputer

ASUS launches the Ascent GX10 personal AI supercomputer, delivering petaflop-scale performance in a compact desktop form.

Global mobile app demand remains resilient as APAC leads growth surge

Adjust’s 2025 Mobile App Growth Report shows global app demand rising, led by APAC’s strong growth in gaming and entertainment.

Related Articles