A critical vulnerability in the Forminator WordPress plugin, used by over 600,000 sites, allows unauthenticated attackers to execute arbitrary code. This is achieved by exploiting a flaw that permits the upload of malicious PHP files. The vulnerability has a high severity rating.

A critical remote code execution (RCE) vulnerability has been reported in the Forminator WordPress plugin, a tool utilized by over 600,000 websites. The flaw reportedly allows unauthenticated attackers to execute arbitrary code on affected sites. This vulnerability carries a high severity rating, indicating a significant risk to the integrity and security of websites employing the plugin.
The mechanism behind this RCE vulnerability involves an exploit that permits the upload of malicious PHP files. In many web applications, the ability to upload files is a necessary feature, but it must be accompanied by robust validation and sanitization to prevent the upload of executable code. When these controls are insufficient, an attacker can upload a specially crafted PHP file, which the web server then interprets and executes, effectively giving the attacker control over the server.
The affected product is the Forminator WordPress plugin. WordPress plugins extend the functionality of the core WordPress content management system, and their widespread adoption means that vulnerabilities in popular plugins can have a broad impact across the internet. Given that Forminator is reportedly active on over 600,000 sites, the potential scope of this vulnerability is substantial.
Typical mitigation strategies for this class of vulnerability include promptly applying vendor-supplied patches and updates. For WordPress users, this means updating the Forminator plugin to a secure version as soon as one becomes available. Additionally, implementing robust file upload validation, ensuring proper file type and content checks, and restricting execution permissions in upload directories are general best practices that can help prevent similar exploits. Web application firewalls (WAFs) can also provide an additional layer of defense by detecting and blocking malicious upload attempts.
This incident underscores the ongoing security challenges associated with third-party components in popular content management systems. The extensive use of plugins and themes in platforms like WordPress means that the security posture of a website is often dependent on the security practices of multiple developers. Regular security audits, timely patching, and adherence to secure coding principles are essential for maintaining a resilient web presence in an environment where new vulnerabilities are continually discovered and exploited.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed