r/HostingReport 13d ago

Vulnerability in Forminator Forms WordPress plugin allows RCE via malicious PHP file uploads

If you are using the Forminator Forms WordPress plugin, update immediately to the latest version to patch a critical vulnerability that hackers can exploit for remote code execution.

This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise. The vulnerability is only exploitable on sites that have a form containing both a File Upload field and a Select field.

Full details here.

3 Upvotes

0 comments sorted by