Gravity Forms Critical Flaw: Hackers Could Upload Code
Good morning. Here are the five WordPress security stories worth knowing about today. First up, a critical vulnerability in Gravity Forms, and this one matters because Gravity Forms powers more than 5 million websites worldwide.
The vulnerability was published yesterday. An attacker doesn’t need a WordPress account. Under a specific form configuration, they can upload a dangerous file to the server, and that can potentially become remote code execution.
There is one important condition: the form needs a file upload field set to hidden. The fix is in Gravity Forms 3.1.1, so if you use Gravity Forms, update to 3.1.1 or later and check any public forms that contain hidden upload fields. When a form accepts files, file validation is a direct security boundary.
Next up, another major form plugin. This time it’s Forminator, which is running on more than 600,000 WordPress sites. A critical vulnerability was published yesterday, and an attacker doesn’t need to log in.
They can potentially make Forminator execute a WordPress shortcode that they control. Now, a shortcode by itself isn’t necessarily dangerous. The real risk depends on what other plugins are installed and what their shortcodes can do.
That’s what makes this one interesting: one vulnerable plugin can potentially reach functionality provided by another. The current release is Forminator 1.57.3, and a security update was released on the 17th of September. So if you use Forminator, update to the latest version.
And if you manage a fleet of sites, this is another reason to think about plugins as a system, not as isolated pieces of software.
Next up is Botiga Pro, and this one has a very simple problem. A WordPress REST endpoint was missing an authorisation check. That means an attacker doesn’t need an account, and they can potentially change WordPress settings directly.
They can also store malicious scripts and even move posts into the trash. In the worst case, that can lead to a complete site takeover. Importantly, a public proof of concept is now available.
The affected versions are anything before 1.6.5, so if you use Botiga Pro, update immediately. The developer has already moved beyond that release with additional security hardening in version 1.6.6.
The lesson here is simple. A REST endpoint is still an administrative interface. If it changes WordPress settings, it must check who is making the request.
Next up, WP Recipe Maker has a newly disclosed critical vulnerability. This plugin is running on more than 50,000 WordPress sites. The problem involves recipe comments.
An attacker can place a WordPress shortcode inside comment content, and when the recipe metadata is later generated, that shortcode can execute on the server. What happens next depends on which shortcodes are available on that website. Some may be harmless; others could expose private information.
The important point is that visitor-controlled text should never become executable instructions. The fix arrived in version 10.8.2 and the current release is 10.8.3. So if you use WP Recipe Maker, update it to 10.8.3, especially if you allow ratings or recipe comments.
And finally this morning, LiteSpeed Cache has a new security disclosure. This one is not as severe as the first four, but the scale is enormous: LiteSpeed Cache is installed on more than 7 million WordPress sites.
The vulnerability affects sites using LiteSpeed’s ESI feature. An attacker can create a malicious request and then trick somebody into opening it. If that person is logged into WordPress, malicious JavaScript could run with their permissions.
There are several conditions needed for the attack. Caching must be enabled, ESI must be enabled, and comments need to be available on a public post. The fix is already available in LiteSpeed Cache 7.9.1, so if you use LiteSpeed Cache, make sure you’re on 7.9.1 or later.
7 million installations means even a lower-severity vulnerability is worth checking, because risk isn't only about the CVSS score. Scale matters, too.
And that’s your WordPress security briefing for today. The big one this morning is Gravity Forms: 5 million websites and a vulnerability that could potentially lead to remote code execution.
Then check your sites for Forminator, Botiga Pro, WP Recipe Maker and LiteSpeed Cache. Patch what you actually run, and verify the update.