Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days

A critical vulnerability in Forminator Forms, a WordPress form builder with more than 600,000 active installations, lets an unauthenticated attacker upload an executable PHP file. It scores 9.8 of 10 and needs no login and no click from anyone. The score describes the worst case. Reaching it needs a form built a particular way and a site configured a … Continue reading Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days