Automatically translated.View original post

A vulnerability was found in the Forminator plug-in on the Wordpress website.

A vulnerability was found in the Forminator plug-in on the Wordpress website, allowing for easy RCE by simply uploading a PHP file.

According to a report by The Hacker News website, a security vulnerability has been detected on a Wordpress plugin called Forminator Forms, a plugin for creating and administering forms on a very popular website. There are more than 6 lakh websites installed. A research team from Wordfence, a security plugin developer on the Wordpress website, says the vulnerability detected is coded CVE-2026-15748, a vulnerability with a danger rating, or CVSS Score, of 9.8 points out of 10, which is called a very serious vulnerability because it opens up a channel for users to use. Upload any file to the website, including an Executable PHP file, which can hack or release malware to the website.

The condition for using this vulnerability is that the form must have a file upload field and a Select Field on the form. The reason why these two fields can be used to upload dangerous files to the site is that Wordpress has revealed that there is a problem in the "handle _ file _ upload ()" function of the plug-in that cannot verify the file type Validation uploaded by the user.

This vulnerability is located on all Forminator Forms versions 1.56.1 and below. Those who are using it can plug it by upgrading it to version 1.56.2 via a patch released for download on July 31. Therefore, ask the person who is currently using this plug-in to check the version and update it immediately.

# Trending # lemon 8 diary # forminator # Wordpress # freedomhack

1 day agoEdited to

... Read moreจากประสบการณ์ส่วนตัว ผมเป็นผู้ดูแลเว็บไซต์ Wordpress ที่ใช้ปลั๊กอิน Forminator ในการสร้างฟอร์มหลายหน้า สำหรับช่องโหว่ที่เพิ่งถูกรายงานนี้ ถือว่าเป็นเรื่องที่น่ากังวลมาก เนื่องจากปลั๊กอินนี้เปิดโอกาสให้แฮกเกอร์สามารถอัปโหลดไฟล์ PHP ที่รันได้บนเซิร์ฟเวอร์ ผ่านช่องทางฟิลด์อัปโหลดไฟล์ (File Upload Field) และฟิลด์เลือก (Select Field) ที่ฟอร์มใช้งานอยู่ จุดสำคัญที่ทำให้เกิดช่องโหว่นี้คือฟังก์ชัน handle_file_upload() ของปลั๊กอินไม่สามารถตรวจสอบประเภทไฟล์ได้อย่างเหมาะสม ทำให้ไม่สามารถกรองไฟล์อันตรายได้ ผมเคยเจอเหตุการณ์ที่เว็บไซต์ถูกโจมตีหลังจากไม่ได้อัปเดตปลั๊กอิน ความเสียหายและกระทบต่อผู้ใช้งานค่อนข้างมาก ดังนั้นการอัปเดตปลั๊กอินเป็นเวอร์ชันล่าสุด 1.56.2 ที่มีการแพทซ์ช่องโหว่ดังกล่าวเป็นสิ่งที่จำเป็นอย่างยิ่ง ผมแนะนำให้ผู้ดูแลเว็บไซต์ Wordpress ทุกคนที่ใช้งาน Forminator รีบตรวจสอบเวอร์ชันและอัปเดตทันทีเพื่อป้องกันเหตุไม่คาดคิด นอกจากนี้ การกำหนดสิทธิ์การอัปโหลดไฟล์อย่างเข้มงวด และตรวจสอบฟิลด์อัปโหลดไฟล์บนฟอร์มอย่างละเอียดก่อนอนุญาตให้ใช้งาน จะช่วยลดความเสี่ยงได้อีกขั้นหนึ่ง ผมเองก็ใช้วิธีนี้ร่วมกับการติดตั้งปลั๊กอินรักษาความปลอดภัยอย่าง Wordfence เพื่อเพิ่มเกราะป้องกันเว็บไซต์ให้แข็งแรงยิ่งขึ้น สุดท้าย ช่องโหว่ในปลั๊กอินยอดนิยมอย่าง Forminator สะท้อนให้เห็นความสำคัญของการอัปเดตซอฟต์แวร์อย่างสม่ำเสมอ และการติดตามข่าวสารด้านความปลอดภัยอย่างใกล้ชิด เพื่อคุ้มครองข้อมูลและการทำงานของเว็บไซต์ไม่ให้ถูกโจมตีได้ง่ายๆ