Public Forminator Forms Let Attackers Upload PHP to WordPress Servers
Forminator through 1.56.1 trusts forged upload settings and misses dangerous pipe-delimited MIME keys. Update to 1.57.1 and check public upload paths for executable files.
Reader edition
Forminator through 1.56.1 trusts forged upload settings and misses dangerous pipe-delimited MIME keys. Update to 1.57.1 and check public upload paths for executable files.
Check Point reproduced kernel file and registry operations through Defender's signed BTR.sys driver. Abuse needs admin rights; behavioral telemetry separates it from cleanup.
Gambit observed Claude Code inside six intrusions. Hunt the test VPN account, rogue LDAP listeners, backup discovery, SQL staging, and firewall restores.
Patch the missing upload check, then audit who can still reach the three remaining weaknesses in the Configuration Manager exploit chain.
Attackers are exploiting a Zimbra SNMP flaw through crafted SMTP requests. Version 10.1.20 fixes it; exposed servers need log and file review.
A blank file entry bypasses Elementor Pro upload checks on exposed forms. Version 4.2.2 fixes the flaw, but patched sites still need to hunt for PHP left behind.
CISA says attackers are exploiting a Windows IKE remote-code flaw; verify April fixed builds and restrict UDP 500 and 4500 until every exposed host is patched.
CISA now ties CVE-2025-60710 to ransomware. The local Windows flaw needs an existing foothold, then lets an attacker elevate to SYSTEM.
A hostile page can rebind its hostname to a Ray dashboard, change Firefox or Safari's User-Agent header, and submit a shell command to the Jobs API.
Pantheon counted 45 million wp2shell attempts in one week. Defenders should verify current WordPress builds and review exposed sites for persistent access.
A compromised crates.io account poisoned three Rust packages. Builds ran a downloader; 2,285 arrayref downloads now require cache, lockfile, and host checks.
USENIX researchers turned writable DIMM configuration into arbitrary physical-memory access. April's Windows update blocks their current chain under Secure Boot.
Chrome 151 fixes five high-severity use-after-free bugs; endpoint inventories must show the fixed build or a later superseding release.