Saturday, 22 November 2025
28.1 C
Singapore
19.5 C
Thailand
21.2 C
Indonesia
27.3 C
Philippines

Critical security breach in popular WordPress plugin impacts over 200,000 installations

Learn about the critical security flaw in the MW WP Form WordPress plugin affecting over 200,000 sites and how to protect your website effectively.

In a recent revelation by Wordfence, a critical security flaw has been discovered in the MW WP Form plugin, affecting versions up to 5.0.1. This vulnerability allows unauthorised individuals to upload arbitrary files, including potentially harmful PHP backdoors. These files can be executed on the server, presenting a significant security risk.

Understanding the MW WP Form plugin

The MW WP Form plugin is famous for creating forms on WordPress websites. It uses a shortcode builder, making it straightforward for users to design and customise forms with various fields and options. A key feature of this plugin is its file upload capability, facilitated by the [mwform_file name= “file”] shortcode. Unfortunately, this feature has become the focal point of the vulnerability.

The nature of the vulnerability

Termed as an Unauthenticated Arbitrary File Upload Vulnerability, this security flaw allows hackers to upload dangerous files to a website without needing registration or authorisation. Such vulnerabilities can escalate to remote code execution, where the uploaded files are executed on the server, potentially allowing attackers to compromise the website and endanger visitors.

The advisory from Wordfence pointed out a defect in the plugin’s file type check mechanism. While it can detect unsafe file types, a runtime exception allows these files to be uploaded regardless. This oversight enables attackers to upload and activate arbitrary PHP files on the server.

Conditions for a successful attack

This vulnerability poses a significant risk, particularly if the “Saving inquiry data in database” option in the plugin settings is enabled. It has been rated as critically severe, scoring 9.8 out of 10.

Wordfence strongly recommends users of the MW WP Form plugin update to the latest version, 5.0.2, where this issue has been addressed. This advice is especially pertinent for users who have activated the “Saving inquiry data in database” option, as the vulnerability does not require any special permissions to be exploited.

Users should refer to the full Wordfence advisory for comprehensive details and guidance.

Hot this week

Rubrik research highlights rising identity threats as AI agents spread across workplaces

Rubrik research shows Singapore organisations face rising identity threats as AI agents expand, driving urgent demand for stronger resilience.

Robot completing household chores sparks debate over the future of home automation

Humanoid robot performs household chores in new video, raising questions about autonomy and the future of home robotics.

Neo4j uses graph intelligence to map fan predictions for Stranger Things’ final season

Neo4j launches HopperGraph, an AI-powered visualisation that maps fan theories to predict the final season of Stranger Things.

From insight to action: TeamViewer introduces Tia for autonomous IT support

TeamViewer launches Tia, an intelligent agent designed to autonomously detect and resolve IT issues across devices and systems.

Apple begins succession planning as Tim Cook considers stepping down next year

Apple is reportedly preparing for Tim Cook’s potential departure as CEO next year, with John Ternus emerging as the top internal successor.

Microsoft adds on-device AI support to the Advanced Paste tool in Windows 11

Microsoft updates Advanced Paste in Windows 11 with on-device AI support, new model options and an improved interface.

WhatsApp brings back About with new visibility and privacy updates

WhatsApp reintroduces its original About feature with new visibility, privacy options, and custom timers.

Sumsub announces dual initiatives to strengthen digital trust in Singapore

Sumsub introduces Singpass integration and a deepfake research partnership with NTU to strengthen digital trust in Singapore.

Google TV may introduce solar-powered remote controls

Google TV may soon feature a solar-powered remote, reducing battery waste and offering an eco-friendly solution for streaming devices.

Related Articles

Popular Categories