WPMU DEV Releases Forminator Security Update After Plugin Briefly Experiments With Giving Everyone Admin
WPMU DEV has released Forminator Pro 1.57.1, a security update fixing a modest assortment of issues including privilege escalation, PHP object injection, cross-site scripting, payment-processing vulnerabilities, Multisite registration problems, and several other items that fall under the technical category of “Jesus Christ, guys.”
The update replaces version 1.57.0, which apparently took WPMU DEV’s famous all-in-one WordPress philosophy a little too seriously.
Hosting? Check.
Backups? Check.
Performance? Check.
Security? Check.
Potentially becoming the administrator of a website you do not own?
We’re exploring new features.
According to the changelog, 1.57.1 fixes a privilege escalation vulnerability, PHP Object Injection, XSS vulnerabilities, security issues involving payment processing, and security improvements to the Hub Connector.
Which is a hell of a list for a plugin whose primary job is supposed to be:
Name:
Email:
Message:
[SUBMIT]
Somehow WPMU DEV managed to turn “Contact Us” into the cybersecurity equivalent of the Normandy landings.
Developers praised the company for quickly releasing the update, while also expressing mild curiosity about how many security vulnerabilities are legally allowed inside one decimal-point release.
“I installed Forminator because I needed a quote-request form,” said one exhausted WordPress developer. “I did not realize I was deploying a financial system, remote-access platform, identity-management suite, and live-fire penetration testing environment.”
WPMU DEV reassured customers by publishing the fixes in its release notes, demonstrating once again the company’s unique ability to make the phrase “security improvements” feel less like reassurance and more like a priest quietly closing the church doors behind you.
Particularly comforting was the entry:
Fix: Security issue affecting payment processing
Ah, excellent.
The money part.
Glad we circled back to that.
Nothing settles the nerves of a small business owner quite like discovering their form plugin had “a security issue affecting payment processing” buried between routine bug fixes like somebody mentioning during dessert that the restaurant kitchen was technically on fire earlier.
The changelog also credits researcher Jakub Herman on multiple fixes, presumably after he opened Forminator, stared into the abyss, and whispered:
“Guys?”
WPMU DEV users are being encouraged to update immediately, which most administrators were already doing because WordPress has conditioned them to react to plugin update notifications with the same urgency normally reserved for tornado sirens.
The good news is that version 1.57.1 patches the reported problems.
The bad news is that WPMU DEV’s marketing department now has to reconsider the slogan:
“Everything you need to manage WordPress.”
because apparently version 1.57.0 also included several things you absolutely did not need.
At press time, WPMU DEV engineers were reportedly preparing Forminator 1.57.2, which contains:
- Improved validation
- Minor UI fixes
- Performance enhancements
- A security patch preventing the newsletter signup form from achieving sentience and purchasing WPMU DEV outright
Users are advised to update promptly and then return to the traditional WordPress security workflow:
Update plugin.
Clear cache.
Check site.
Check forms.
Check payment gateway.
Check admin users.
Check logs.
Wonder why you didn’t become a plumber.
