Wednesday, 5 November 2025
29.9 C
Singapore
24 C
Thailand
21.9 C
Indonesia
28.3 C
Philippines

Critical security breach in popular WordPress plugin impacts over 200,000 installations

Learn about the critical security flaw in the MW WP Form WordPress plugin affecting over 200,000 sites and how to protect your website effectively.

In a recent revelation by Wordfence, a critical security flaw has been discovered in the MW WP Form plugin, affecting versions up to 5.0.1. This vulnerability allows unauthorised individuals to upload arbitrary files, including potentially harmful PHP backdoors. These files can be executed on the server, presenting a significant security risk.

Understanding the MW WP Form plugin

The MW WP Form plugin is famous for creating forms on WordPress websites. It uses a shortcode builder, making it straightforward for users to design and customise forms with various fields and options. A key feature of this plugin is its file upload capability, facilitated by the [mwform_file name= “file”] shortcode. Unfortunately, this feature has become the focal point of the vulnerability.

The nature of the vulnerability

Termed as an Unauthenticated Arbitrary File Upload Vulnerability, this security flaw allows hackers to upload dangerous files to a website without needing registration or authorisation. Such vulnerabilities can escalate to remote code execution, where the uploaded files are executed on the server, potentially allowing attackers to compromise the website and endanger visitors.

The advisory from Wordfence pointed out a defect in the plugin’s file type check mechanism. While it can detect unsafe file types, a runtime exception allows these files to be uploaded regardless. This oversight enables attackers to upload and activate arbitrary PHP files on the server.

Conditions for a successful attack

This vulnerability poses a significant risk, particularly if the “Saving inquiry data in database” option in the plugin settings is enabled. It has been rated as critically severe, scoring 9.8 out of 10.

Wordfence strongly recommends users of the MW WP Form plugin update to the latest version, 5.0.2, where this issue has been addressed. This advice is especially pertinent for users who have activated the “Saving inquiry data in database” option, as the vulnerability does not require any special permissions to be exploited.

Users should refer to the full Wordfence advisory for comprehensive details and guidance.

Hot this week

VoidZero secures US$12.5 million Series A to launch unified JavaScript toolchain Vite+

VoidZero raises US$12.5 million Series A to launch Vite+, a unified JavaScript toolchain aimed at boosting developer productivity.

Univers launches world-first Global Impact AI Lab with AMD, Microsoft, and NUS

Univers launches Global Impact AI Lab with AMD, Microsoft, and NUS to accelerate enterprise AI and IoT innovation in Singapore.

Red Hat honours DBS and DIS for innovation at APAC Innovation Awards 2025

Red Hat recognises DBS Bank and Singapore’s Digital and Intelligence Service for AI and open source innovation at the 2025 APAC Awards.

Apple may launch an affordable Mac laptop in early 2026

Apple may launch its first affordable Mac laptop in early 2026, aiming to attract students and everyday users with a price under US$1,000.

Mixed Reality Link is now available on Windows 11 and Meta Quest headsets

Meta’s Mixed Reality Link brings immersive Windows 11 productivity to all Meta Quest 3 and 3S users, offering a low-cost virtual workspace.

Google explores orbital data centres for sustainable AI computing

Google explores powering AI from space with Project Suncatcher, aiming to use solar-powered satellites for sustainable data processing.

DJI unveils Osmo Mobile 8 with Apple DockKit integration and pet tracking

DJI’s new Osmo Mobile 8 gimbal features an Apple DockKit, 360-degree rotation, and pet tracking for enhanced creative control.

Final Fantasy Tactics modders restore missing bonus content to The Ivalice Chronicles remaster

Fans are restoring missing Final Fantasy Tactics features through mods, bringing back War of the Lions content for the new remaster.

Motorola refreshes Moto G and Moto G Play smartphones for 2026

Motorola launches new Moto G and Moto G Play models for 2026, featuring upgraded cameras, improved displays, and stylish Pantone colour options.

Related Articles

Popular Categories