• Advertise
  • Support Center
Saturday, July 12, 2025
  • Login
  • Register
INNOCENT MICHAEL
  • HOME
  • MAIN CATEGORY
    • BREAKING NEWSUPDATES
      • BROWSE
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • USA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • CANADA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • UK NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • NIGERIA NEWS
        • Browser News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
    • WATCHVIDEOS
    • AUDIOPODCAST
    • BULLETIN
    • BUSINESS NEWS
    • CYBERSECURITY
    • ENTERTAINMENT
      • NEWS
    • TECHNOLOGY
      • TECH NEWS
      • HOMELAB
    • REDCARPET CHRONICLE
    • POLITICSNEWS
      • BROWSE
      • POLITICS NEWS (CA)
      • POLITICS NEWS (USA)
      • POLITICS NEWS (UK)
    • SPORTS
      • SPORTS UPDATE
      • AEW
      • WWE
  • SHOP
    • Browse Shop
  • QUICK LINKS
    • OUR PLATFORMS
  • LEGAL HUB
    • Wikipedia
    • ABOUT US
    • OUR EDITORIAL PHILOSOPY
Live TV Indicator
WATCH ONLINE TV
No Result
View All Result
INNOCENT MICHAEL
  • HOME
  • MAIN CATEGORY
    • BREAKING NEWSUPDATES
      • BROWSE
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • USA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • CANADA NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • UK NEWS
        • Browse News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
      • NIGERIA NEWS
        • Browser News
        • Local News
        • Breaking News
        • Society & Culture
        • Crisis & Controversy
        • Economy & Markets
        • Tech & Innovation
    • WATCHVIDEOS
    • AUDIOPODCAST
    • BULLETIN
    • BUSINESS NEWS
    • CYBERSECURITY
    • ENTERTAINMENT
      • NEWS
    • TECHNOLOGY
      • TECH NEWS
      • HOMELAB
    • REDCARPET CHRONICLE
    • POLITICSNEWS
      • BROWSE
      • POLITICS NEWS (CA)
      • POLITICS NEWS (USA)
      • POLITICS NEWS (UK)
    • SPORTS
      • SPORTS UPDATE
      • AEW
      • WWE
  • SHOP
    • Browse Shop
  • QUICK LINKS
    • OUR PLATFORMS
  • LEGAL HUB
    • Wikipedia
    • ABOUT US
    • OUR EDITORIAL PHILOSOPY
  • Login
  • Register
No Result
View All Result
INNOCENT MICHAEL
Home MITRE ATT&CK
WPForms Plugin Vulnerability Risks Millions of WordPress Websites

WPForms Plugin Vulnerability Risks Millions of WordPress Websites

in MITRE ATT&CK, Threat Hunting, Wordpress
0
Share on FacebookShare On Whatsapp

The widely used WPForms plugin, installed on up to 6 million WordPress websites, has patched a critical vulnerability that could expose sites to unauthorized data modifications. The flaw allows attackers to update subscriptions and issue refunds without proper privileges.

The Root Cause: Missing Capability Check

The vulnerability lies in the wpforms_is_admin_page function, which lacks a capability check. This oversight fails to verify user permissions, enabling attackers to modify data even with basic subscriber-level access.

Key Details:

  • Affected Versions: WPForms versions 1.8.4 to 1.9.2.1.
  • Impact: Unauthorized subscription updates and payment refunds.
  • Severity: High, especially for sites with subscriber-level users who pay for services.
  • Access Requirements: Attackers need subscriber-level credentials to exploit this flaw.

According to Wordfence, this vulnerability is severe due to the potential impact on websites with paid memberships or subscriptions.

Wordfence Statement:

“The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpforms_is_admin_page function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.”

What Should Site Owners Do?

To safeguard your site, it’s critical to take immediate action:

  1. Update the Plugin: Upgrade WPForms to version 1.9.2.2 or higher.
  2. Review Permissions: Audit user roles and ensure that subscriber-level accounts are only assigned when necessary.
  3. Monitor Activity: Keep an eye on suspicious activity, particularly subscription or refund modifications.

How to Update WPForms

  1. Log in to your WordPress dashboard.
  2. Navigate to Plugins > Installed Plugins.
  3. Locate WPForms and click Update Now if an update is available.

Stay Secure

Maintaining updated plugins is a crucial aspect of website security. Regularly monitor your WordPress environment and stay informed about vulnerabilities to mitigate risks.

ShareSendTweetShareShare

Related Posts

WP Plugin Auth Bypass Exploited: Urgent Update Required
Wordpress

WP Plugin Auth Bypass Exploited: Urgent Update Required

April 11, 2025
17
WordPress Plugin 100K Sites at Risk of Code Execution
Tech

WordPress Plugin 100K Sites at Risk of Code Execution

March 5, 2025
23
Automattic Faces Backlash from WordPress Community Over Recent Changes
Wordpress

Automattic Faces Backlash from WordPress Community Over Recent Changes

January 11, 2025
8
3 Million WordPress Sites at Risk: Backup Plugin Vulnerability Alert
Apps

3 Million WordPress Sites at Risk: Backup Plugin Vulnerability Alert

January 7, 2025
43
Critical RCE Vulnerability: Is Your WordPress Site at Risk?
Cyber Awareness

Critical RCE Vulnerability: Is Your WordPress Site at Risk?

December 25, 2024
10
Judge Rules in Favor of WP Engine in Legal Dispute with Automattic
Tech

Judge Rules in Favor of WP Engine in Legal Dispute with Automattic

December 20, 2024
40
Subscribe
Login
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
video
play-rounded-fill

Stay Updated

Subscribe to our newsletter and be the first to receive updates, tips, and exclusive offers straight to your inbox.

Haysuite Haysuite Haysuite
The UK’s phone theft crisis is a wake-up call for digital security
Hackers

The UK’s phone theft crisis is a wake-up call for digital security

April 19, 2025
36
7 Clever Ways to Reuse Your Old Windows 10 PC
Tech

7 Clever Ways to Reuse Your Old Windows 10 PC

April 19, 2025
25
8 Proven Ways to Clear Clipboard on Windows 11 Safely
Windows

8 Proven Ways to Clear Clipboard on Windows 11 Safely

April 18, 2025
18
What to Do When Ransomware Hits: Pay or Prepare?
Ransomware

What to Do When Ransomware Hits: Pay or Prepare?

April 18, 2025
14
Meta Resumes EU AI Training: Why Europe’s Data Matters
AI

Meta Resumes EU AI Training: Why Europe’s Data Matters

April 16, 2025
25

© 2024 Innocent Michael Network Inc..

  • Wikipedia
  • CRM
  • Submit Your Article
  • Support
  • Legal
Menu
  • Wikipedia
  • CRM
  • Submit Your Article
  • Support
  • Legal

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Sign Up with Facebook
Sign Up with Google
Sign Up with Linked In
OR

Fill the forms below to register

*By registering into our website, you agree to the Terms & Conditions and Privacy Policy.
All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Login
  • Sign Up
Live TV Indicator
WATCH ONLINE TV
  • HOME
  • BROWSE
    • WATCH
    • AUDIO
    • BULLETIN
    • BUSINESS NEWS
    • CYBERSECURITY
    • TECHNOLOGY
      • TECH NEWS
      • HOMELAB
    • REDCARPET CHRONICLE
  • NEWS
    • GLOBAL NEWS
    • USA NEWS
    • CANADA NEWS
    • UK NEWS
    • NIGERIA NEWS
  • POLITICS
    • POLITICS NEWS (GLOBAL)
    • POLITICS NEWS (CA)
    • POLITICS NEWS (USA)
    • POLITICS NEWS (UK)
  • SPORTS NEWS
    • SPORTS NEWS (GLOBAL)
    • AEW NEWS
    • SOCCER NEWS
    • WWE NEWS
  • SHOP
  • QUICK LINKS
  • LEGAL HUB

Copyright © 2024 INNOCENT MICHAEL NETWORK INC.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply