Popular WPForms Lite put a backdoor in their plugin
hackerbeat
18 points
1 comment
August 09, 2026
Related Discussions
Found 5 related stories in 84.1ms across 8,687 title embeddings via pgvector HNSW
- Pre-Authentication RCE in WordPress Core patrikg · 18 pts · July 17, 2026 · 56% similar
- WordPress: Unauthenticated path traversal leading to conditional RCE vntok · 178 pts · September 22, 2026 · 54% similar
- Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents fishthethis · 11 pts · September 17, 2026 · 47% similar
- I found a WordPress RCEs with GPT5.6 and $25 infosecau · 388 pts · July 20, 2026 · 47% similar
- Sourcehut account takeover via build logs (XSS in ansi2html) arusekk · 93 pts · September 24, 2026 · 41% similar
Discussion Highlights (1 comments)
no-name-here
It seems like backdoor is not the right term? From that thread, as part of their setup wizard, it appears they use a 1 hour token which allows installation of additional plugins if you choose to . If so, to use a slightly stretched analogy, it would be like an app’s setup wizard (that requires admin) allowed you (as admin) to optionally install additional items as part of the wizard (while it still has admin rights).