WPMU DEV Releases Forminator Security Update After Plugin Briefly Experiments With Giving Everyone Admin

WPMU DEV has released Forminator Pro 1.57.1, a security update fixing a modest assortment of issues including privilege escalation, PHP object injection, cross-site scripting, payment-processing vulnerabilities, Multisite registration problems, and several other items that fall under the technical category of “Jesus Christ, guys.”

The update replaces version 1.57.0, which apparently took WPMU DEV’s famous all-in-one WordPress philosophy a little too seriously.

Hosting? Check.

Backups? Check.

Performance? Check.

Security? Check.

Potentially becoming the administrator of a website you do not own?

We’re exploring new features.

According to the changelog, 1.57.1 fixes a privilege escalation vulnerability, PHP Object Injection, XSS vulnerabilities, security issues involving payment processing, and security improvements to the Hub Connector.

Which is a hell of a list for a plugin whose primary job is supposed to be:

Name:
Email:
Message:
[SUBMIT]

Somehow WPMU DEV managed to turn “Contact Us” into the cybersecurity equivalent of the Normandy landings.

Developers praised the company for quickly releasing the update, while also expressing mild curiosity about how many security vulnerabilities are legally allowed inside one decimal-point release.

“I installed Forminator because I needed a quote-request form,” said one exhausted WordPress developer. “I did not realize I was deploying a financial system, remote-access platform, identity-management suite, and live-fire penetration testing environment.”

WPMU DEV reassured customers by publishing the fixes in its release notes, demonstrating once again the company’s unique ability to make the phrase “security improvements” feel less like reassurance and more like a priest quietly closing the church doors behind you.

Particularly comforting was the entry:

Fix: Security issue affecting payment processing

Ah, excellent.

The money part.

Glad we circled back to that.

Nothing settles the nerves of a small business owner quite like discovering their form plugin had “a security issue affecting payment processing” buried between routine bug fixes like somebody mentioning during dessert that the restaurant kitchen was technically on fire earlier.

The changelog also credits researcher Jakub Herman on multiple fixes, presumably after he opened Forminator, stared into the abyss, and whispered:

“Guys?”

WPMU DEV users are being encouraged to update immediately, which most administrators were already doing because WordPress has conditioned them to react to plugin update notifications with the same urgency normally reserved for tornado sirens.

The good news is that version 1.57.1 patches the reported problems.

The bad news is that WPMU DEV’s marketing department now has to reconsider the slogan:

“Everything you need to manage WordPress.”

because apparently version 1.57.0 also included several things you absolutely did not need.

At press time, WPMU DEV engineers were reportedly preparing Forminator 1.57.2, which contains:

  • Improved validation
  • Minor UI fixes
  • Performance enhancements
  • A security patch preventing the newsletter signup form from achieving sentience and purchasing WPMU DEV outright

Users are advised to update promptly and then return to the traditional WordPress security workflow:

Update plugin.

Clear cache.

Check site.

Check forms.

Check payment gateway.

Check admin users.

Check logs.

Wonder why you didn’t become a plumber.

BEAVER BUILDER RELEASES EMERGENCY HOTFIX AFTER DISCOVERING WEBSITE BUILDER WAS ALSO BUILDING ATTACK VECTORS

August 12, 2026 — Beaver Builder developers released version 2.11.0.2 Wednesday after discovering that several innocent-looking form fields had apparently spent the summer pursuing careers in cybersecurity.

The hotfix addresses multiple security issues, including possible XSS in the Button module, possible XSS in the Search module, and arbitrary shortcode execution — a feature users reportedly did not remember requesting.

“We really wanted the Button module to focus on being a button,” said one exhausted WordPress administrator. “Apparently it had other ambitions.”

According to the changelog, Beaver Builder also fixed corrupt serialization in popup templates, rewrite rules firing on every admin initialization, multisite version-writing problems, broken RTL overlays, invisible global-column overlays, and a History event firing when it wasn’t supposed to.

Industry experts praised the release for finally restoring Beaver Builder’s traditional workflow:

  1. Update plugin.
  2. Discover new problem.
  3. Read changelog.
  4. Whisper “what the fuck.”
  5. Update plugin again.
  6. Clear cache.
  7. Clear Cloudflare.
  8. Clear browser cache.
  9. Clear Beaver Builder cache.
  10. Clear your schedule.

The company emphasized that version 2.11.0.2 is a “hotfix,” a WordPress industry term meaning, “Please install this immediately, but also maybe don’t touch anything afterward.”

Administrators managing multiple WordPress sites confirmed they are excited to spend the remainder of the afternoon opening 14 dashboards and clicking UPDATE NOW while quietly wondering which perfectly functional page will emerge with a 4,700-pixel-wide button.

At press time, Beaver Builder had reportedly begun work on version 2.11.0.3 after a developer noticed the Spacer module had acquired root access to the server.

LOCAL MAN LEARNS HIS WEBSITE HAS BEEN VULNERABLE TO “CACHE POISONING,” IMMEDIATELY ASSUMES RUSSIANS ARE INSIDE THE WORDPRESS

SCHAUMBURG, IL — A local website administrator reportedly entered a state of heightened national-security readiness Tuesday after discovering that his domain had been operating without DNSSEC, leaving it theoretically vulnerable to something called “cache poisoning.”

“Excuse me, poisoning?” the man said, staring at a DNS settings page he had peacefully ignored for approximately 14 years. “I thought the worst thing that could happen was Yoast giving me an orange circle.”

According to cybersecurity experts, DNS cache poisoning involves tricking DNS resolvers into accepting forged information, potentially sending users to the wrong server.

According to the website owner, however, it apparently means “someone can put anthrax in Cloudflare.”

The situation escalated after the documentation explained that enabling DNSSEC adds “cryptographic digital signatures” to DNS records.

“Oh, good,” he reportedly said. “So my fucking domain needs notarized blockchain paperwork now.”

Sources confirmed that just minutes earlier, the website had appeared completely normal.

Then the administrator read the phrase:

“Visitors are cryptographically protected against cache poisoning and forged DNS data.”

At that point, every successful website visit since 2009 was retroactively reclassified as “an absolute miracle.”

The man then spent several minutes clicking through registrar settings looking for the DNSSEC toggle while becoming increasingly concerned by terms including:

Delegation Signer

Key Tag

Algorithm

Digest

Digest Type

None of which, experts confirmed, resemble anything a normal person expects to encounter while maintaining a website for a concrete company.

“This morning I was changing a PDF link,” the administrator said. “Now apparently I’m exchanging cryptographic proof with the root DNS infrastructure so Belarus can’t hijack the product data sheet for a joint sealant.”

Cybersecurity officials stressed that DNSSEC is a legitimate and useful security technology.

They also acknowledged there was probably no need to describe the alternative as “VULNERABLE TO CACHE POISONING” directly beside an ENABLE button.

“You could just say ‘adds protection against forged DNS responses,’” said one exhausted IT professional. “But then nobody would experience the exhilarating sensation that their domain registrar just diagnosed their website with ricin poisoning.”

At press time, the administrator had successfully enabled DNSSEC and was enjoying approximately eleven seconds of peace before noticing another security dashboard warning:

“CAA RECORD NOT CONFIGURED.”

“WHAT THE FUCK IS THAT.”

UptimeRobot Unveils Revolutionary SEO Strategy Of Waiting For Literally Everything Else On Internet To Break

DALLAS — Website-monitoring service UptimeRobot announced Tuesday that it had achieved a major breakthrough in search engine optimization after realizing millions of people begin every technology problem by typing “IS THIS FUCKING THING DOWN” into Google.

According to industry data, UptimeRobot is now ranking for an astonishing collection of humanity’s digital distress signals, including:

“is ChatGPT down”
“yahoo mail down”
“is roblox down”
“character ai down”
“is steam down”
“is fortnite down”
“is snapchat down”
“is TikTok down”
“is AWS down”

“We spent years building a sophisticated uptime-monitoring platform,” said one company engineer, quietly closing 47 Grafana dashboards. “Turns out the real product was answering panicked Google searches from people who refreshed Roblox twice.”

SEO experts praised the strategy as virtually recession-proof.

“Most companies have to create demand,” said one analyst. “UptimeRobot simply waits for Amazon, OpenAI, TikTok, Yahoo, Fortnite, Snapchat, Roblox, Steam, or modern civilization itself to shit the bed.”

At press time, UptimeRobot’s content team had reportedly completed its 2027 editorial calendar:

Is Google Down?
Is Microsoft Down?
Is The Internet Down?
Is My Router Down?
Is Society Down?
Is God Down?

AI Detector Confirms Article Written In 2014 Was 35% Created By Technology That Wouldn’t Exist For Another Eight Years

INTERNET — A leading AI-content detector announced Tuesday that it had successfully identified traces of artificial intelligence in an article written in 2014, providing researchers with the strongest evidence yet that ChatGPT may possess the ability to travel backward through time.

“This passage is clearly suspicious,” said the detector, examining several paragraphs typed by an actual human nearly a decade before ChatGPT existed. “The sentence structure displays characteristics commonly associated with GPT models, particularly the unsettling use of complete sentences.”

Experts immediately praised the breakthrough.

“For years, physicists believed time travel would require exotic matter, wormholes, or enormous amounts of energy,” said one researcher. “Apparently all you actually need is Grammarly and a paragraph with decent transitions.”

The discovery came after a writer deliberately produced an article without AI assistance, then submitted the exact same text to several AI detectors.

Results showed the article was:

100% AI.

78% AI.

42% AI.

Human.

And, according to two additional services, “$19.99 per month to find out.”

Industry leaders said the wildly contradictory findings demonstrate just how sophisticated AI detection technology has become.

“The important thing isn’t whether the result is correct,” explained one detector company spokesperson. “The important thing is that there is a large percentage displayed next to a circular progress bar.”

Researchers later expanded testing to articles written in 2014, 2019, and 2021.

Several were flagged for possible AI involvement.

“This strongly suggests one of two possibilities,” said analysts. “Either AI detectors are unreliable, or a freelance SEO writer accidentally invented generative artificial intelligence sometime during the Obama administration and simply forgot to mention it.”

Detector companies rejected criticism, stressing that their products should never be treated as definitive proof unless, of course, an employer, professor, editor, client, school administrator, or nervous marketing manager desperately wants them to be.

Meanwhile, genuinely AI-generated articles reportedly passed several detectors after a human changed four sentences and replaced “Furthermore” with “Also.”

At press time, an AI detector examining the Declaration of Independence had rated it 71% GPT-generated and recommended that Thomas Jefferson “rewrite the flagged passages in his own words.”

BREAKING: Zuckerberg’s $300 Million Yacht Unable To Hear Distress Call Over Deafening Sound Of Being A $300 Million Yacht

ALASKA — Representatives for Mark Zuckerberg confirmed Monday that the crew aboard his 387-foot superyacht Launchpad did not hear repeated radio calls asking nearby vessels to assist a small stranded boat, explaining that the signal was likely drowned out by the yacht’s state-of-the-art Billionaire Acoustic Shielding System.

“The vessel was operating normally,” a Meta spokesperson said. “Unfortunately, radio frequencies originating from people who have run out of gas are automatically classified as low-value engagement.”

The stranded skiff was ultimately helped by a cruise ship farther away, after Zuckerberg’s yacht reportedly failed to respond despite being closer.

Maritime experts stressed there was no reason to assume anything improper occurred.

“Superyachts are incredibly sophisticated vessels,” said marine analyst Kevin Broderick. “They can detect underwater obstacles, track satellites, stabilize themselves in 15-foot seas, and probably identify a bottle of champagne entering the wrong refrigerator from 200 yards away. But sometimes ‘Hey, can you help us?’ simply exceeds the limits of modern technology.”

Meta clarified that Zuckerberg and his family were not aboard at the time, meaning the crew had unfortunately been forced to ignore ordinary people entirely on their own initiative.

According to the company, the yacht eventually became aware of the Coast Guard message after checking a different radio channel, at which point another vessel had already provided assistance.

“We’re grateful everyone is safe,” the spokesperson added, before confirming Meta engineers are developing a future software update allowing Launchpad to recognize distress calls from accounts with fewer than 10,000 followers.

At press time, the stranded boat had reportedly been advised that next time it should try contacting the yacht through Instagram Reels.

BREAKING: Gravity Forms 3.0.2 Successfully Converts Functional Websites Into Interactive Troubleshooting Experiences

WASHINGTON — Gravity Forms announced Monday that version 3.0.2 has successfully completed the company’s long-awaited transition from “WordPress form plugin” to “full-time employment opportunity.”

The update, which introduces an exciting collection of broken input masks, mysterious styling changes, JavaScript surprises, and workflows that worked perfectly fine five minutes ago, has already been praised by developers who were worried they might accidentally enjoy their afternoon.

“We really wanted to rethink what a form plugin could be,” said a Gravity Forms spokesperson while slowly pushing a production database into traffic. “Why should entering a phone number simply work when it could instead become a three-hour investigation involving browser consoles, changelogs, CSS overrides, rollback packages, and an email from support telling you not to roll back?”

Users upgrading from Gravity Forms 2.10.5 reportedly experienced the innovative new “What The Fuck Is This?” onboarding sequence, in which previously functioning websites immediately encourage administrators to question every decision they have made since installing WordPress.

The company also introduced its groundbreaking new compatibility philosophy:

“If you have hundreds of fields configured a certain way, simply change all of them.”

Industry analysts called the strategy “bold,” “disruptive,” and “technically much easier for Gravity Forms than for you.”

One developer managing more than 10 websites reportedly spent hours reverting installations to an older version, only to later discover a support email stating:

“Note that we do not recommend reverting installations that have already upgraded.”

The email then helpfully included a link to the older version.

At press time, Gravity Forms 3.0.2 was functioning normally on a fresh WordPress installation containing one form, one text field, no plugins, no custom CSS, no users, and absolutely nothing anyone has ever built in the real world.

Gravity Forms 3.0 Introduces Exciting New Feature Where Input Masks Become the Input

WordPress administrators nationwide celebrated this week after upgrading to Gravity Forms 3.0 and discovering that the plugin’s new input-masking system has dramatically streamlined the form-building process by simply displaying the mask itself to users.

“Before, when we entered 9?99, customers could type a number between one and three digits,” said one website administrator foolish enough to believe that functionality would continue. “Now the field proudly says 9?99 right inside the box. Much more transparent.”

The innovation arrives after Gravity Forms replaced the masking library that had successfully handled existing forms for years.

Company officials reportedly reassured users that the question mark remains fully supported, provided customers understand that “supported” can occasionally mean “visibly printed into the form like an ancient rune.”

The upgrade has been especially welcomed by organizations with hundreds of existing masked fields.

“I was worried I might have something productive to do today,” said one developer managing 400 product quantity fields. “Thankfully, a major plugin update has given me the opportunity to individually revisit configuration decisions I made seven years ago.”

Phone masks such as (999) 999-9999 reportedly continue functioning normally, further enhancing the debugging experience by making the problem just inconsistent enough to ruin an entire afternoon.

Gravity Forms experts have recommended several possible solutions, including disabling the masks, rebuilding the fields, changing field types, writing custom JavaScript, rolling back the plugin, filing a support ticket, sacrificing a USB cable under a full moon, or simply explaining to customers that 9?99 is the quantity they ordered.

At press time, the Gravity Forms documentation continued to describe ? as the character used to designate optional portions of a mask, leading developers to conclude that the documentation and the JavaScript library are currently “taking some time apart.”

Gravity Forms 3.1 is expected to introduce another major usability improvement in which conditional logic conditions are displayed directly to customers as PHP arrays.

New Study Finds People Who Curse At AI Just One Loading Spinner Away From Challenging Microwave To Fistfight

CAMBRIDGE, MA — A groundbreaking new psychology study has identified a distinct personality type known as “the person who says ‘you useless fucking idiot’ to an AI chatbot because it bolded the wrong sentence.”

Researchers say the behavior usually begins innocently.

“I asked it not to use bullet points,” said one participant, visibly shaking. “Then it used three bullet points. At that moment, it stopped being software and became my enemy.”

Scientists initially believed users were simply frustrated with technology. But after reviewing thousands of interactions, researchers discovered something much deeper: humans will form an emotionally intense adversarial relationship with literally anything that responds to them.

“It doesn’t matter that the AI has no feelings,” explained lead researcher Dr. Melissa Grant. “The user has enough feelings for both parties.”

Common warning signs include:

Calling the AI “dumbass” before immediately asking it another question.

Threatening to switch to a competing AI, then returning 14 seconds later.

Writing “I SAID NO FUCKING MARKDOWN” with the intensity of a hostage negotiator.

Interpreting a slightly incorrect answer as evidence the machine has become lazy, arrogant, or “full of shit lately.”

Saying “finally” after the AI completes a task correctly, as though supervising a disappointing nephew at his first job.

Psychologists say the phenomenon is closely related to people yelling “COME ON” at printers, insulting GPS navigation systems, and pressing elevator buttons harder after determining the elevator has deliberately chosen to disrespect them.

The study also found that 94% of people who verbally abuse AI continue using it immediately afterward.

“They’re not ending the relationship,” Grant said. “They’re fighting for the relationship.”

At press time, researchers were forced to suspend the study after an AI generated an unnecessary introductory paragraph and 37 participants simultaneously screamed, “JUST GIVE ME THE FUCKING ANSWER.”

Patchstack Urges WordPress Admins to Immediately Update From Version They Are Not Running

WordPress administrators were placed on heightened alert Friday after security platform Patchstack warned that WordPress versions below 7.0.3 contain a medium-severity SSRF vulnerability, prompting widespread concern among users already running WordPress 7.0.3.

“WordPress < 7.0.3 — SSRF vulnerability,” read the urgent security notice, directly above information confirming the website had successfully updated to WordPress 7.0.3 earlier that morning.

Sources confirmed the warning was especially terrifying because of the advanced mathematical concept involved.

“Apparently anything less than 7.0.3 is vulnerable,” said one shaken administrator, staring at a dashboard displaying version 7.0.3. “Unfortunately, I have no way of knowing whether 7.0.3 is less than 7.0.3 without contacting our hosting provider.”

Patchstack classified the issue as Low Priority, Not Known to be Exploited, and affecting versions the website is no longer using, creating what cybersecurity professionals call “the full panic package.”

The dashboard provided administrators with several critical pieces of information:

Vulnerable versions: < 7.0.3
Installed version: 7.0.3
Known exploitation: None
Required action: Apparently develop anxiety anyway

Industry experts praised the notification for ensuring that even completely patched websites can still enjoy the psychological benefits of having a security problem.

“This is an important innovation,” said cybersecurity analyst Thomas Keller. “Historically, once you patched a vulnerability, the fear would go away. Platforms like Patchstack are solving that.”

Administrators were reportedly advised to review the vulnerability details, verify their version number six additional times, clear every cache on the server, check Reddit, open a support ticket with their host, and briefly consider abandoning WordPress entirely before remembering that nothing is actually wrong.

At press time, Patchstack was reportedly testing a new alert system capable of notifying users about additional threats they have already fixed.

Upcoming notices include:

PHP Version You No Longer Use Contains Vulnerability

Plugin You Deleted in 2021 May Be Exploited

WordPress 6.4.2 Vulnerable — You Are Running 7.0.3, But Imagine If You Weren’t

Security Issue Successfully Resolved — Click Here to Panic