Thursday, 23 October 2025
28.9 C
Singapore
24.3 C
Thailand
20.8 C
Indonesia
29 C
Philippines

Critical security breach in popular WordPress plugin impacts over 200,000 installations

Learn about the critical security flaw in the MW WP Form WordPress plugin affecting over 200,000 sites and how to protect your website effectively.

In a recent revelation by Wordfence, a critical security flaw has been discovered in the MW WP Form plugin, affecting versions up to 5.0.1. This vulnerability allows unauthorised individuals to upload arbitrary files, including potentially harmful PHP backdoors. These files can be executed on the server, presenting a significant security risk.

Understanding the MW WP Form plugin

The MW WP Form plugin is famous for creating forms on WordPress websites. It uses a shortcode builder, making it straightforward for users to design and customise forms with various fields and options. A key feature of this plugin is its file upload capability, facilitated by the [mwform_file name= “file”] shortcode. Unfortunately, this feature has become the focal point of the vulnerability.

The nature of the vulnerability

Termed as an Unauthenticated Arbitrary File Upload Vulnerability, this security flaw allows hackers to upload dangerous files to a website without needing registration or authorisation. Such vulnerabilities can escalate to remote code execution, where the uploaded files are executed on the server, potentially allowing attackers to compromise the website and endanger visitors.

The advisory from Wordfence pointed out a defect in the plugin’s file type check mechanism. While it can detect unsafe file types, a runtime exception allows these files to be uploaded regardless. This oversight enables attackers to upload and activate arbitrary PHP files on the server.

Conditions for a successful attack

This vulnerability poses a significant risk, particularly if the “Saving inquiry data in database” option in the plugin settings is enabled. It has been rated as critically severe, scoring 9.8 out of 10.

Wordfence strongly recommends users of the MW WP Form plugin update to the latest version, 5.0.2, where this issue has been addressed. This advice is especially pertinent for users who have activated the “Saving inquiry data in database” option, as the vulnerability does not require any special permissions to be exploited.

Users should refer to the full Wordfence advisory for comprehensive details and guidance.

Hot this week

GigaDevice opens new Tokyo office to strengthen Japan presence and global collaboration

GigaDevice opens a new Tokyo office to strengthen local services, deepen collaboration, and drive innovation in Japan’s semiconductor market.

Facebook’s new AI feature scans users’ camera rolls for unpublished photos

Facebook’s new AI tool scans users’ camera rolls to suggest edits and collages, raising questions about data use and privacy.

SFIC unveils five-year roadmap to strengthen Singapore’s furniture industry

SFIC launches its 2026–2030 roadmap to drive innovation, digitalisation, and global growth for Singapore’s furniture industry.

Hitachi Vantara partners with Supermicro to boost AI and enterprise data performance

Hitachi Vantara partners with Supermicro to strengthen enterprise AI, combining unified storage with GPU compute for modern data workloads.

HPE and Ericsson launch joint validation lab for next-generation 5G core networks

HPE and Ericsson launch a joint validation lab to develop and test cloud-native dual-mode 5G core solutions for seamless multi-vendor deployments.

GM introduces hands-free, eyes-off driving for Escalade IQ in 2028

GM unveils plans for hands-free, eyes-off driving in the Escalade IQ by 2028, alongside AI voice assistants, robotics, and energy innovations.

Meta cuts 600 roles across AI division amid restructuring

Meta cuts 600 jobs in its AI division as it restructures teams and shifts focus to its new superintelligence project, TBD Lab.

DJI Mic Mini review: A pocket-sized wireless mic that punches above its weight

DJI Mic Mini is a pocket-sized wireless mic offering crisp audio, noise cancellation, long-range stability, and easy pairing with cameras and smartphones.

OpenAI launches ChatGPT Atlas, a browser built around AI assistance

OpenAI launches ChatGPT Atlas, a new browser with built-in AI that helps users browse, plan, and work more efficiently.

Related Articles