PostLog inSign upPostSybre Waaijer@SybreWaaijerSyed Balkhi (Awesome Motive) put a backdoor in WPForms Lite three weeks ago in version 2.0.0. The plugin runs on over 5 million sites. The file: wpforms-lite/src/SetupWizard/Bridge.php. What it does: It takes over your browser and opens their app on WPForms' servers. It hands that app a one-hour login token for your site. Their app can then act on your behalf on your site. What they can do with it: Their app can install and activate plugins. It can also turn on a switch that starts sending your form submissions to WPForms' servers. The plugin never asks first and never warns you. When it runs: It kicks in automatically on a fresh install during setup, only for administrators. You won't get a notice. The token expires at the end of setup, or after an hour. What they can install: Thirteen plugins from WordPress dot org: WP Mail SMTP, WPConsent, Uncanny Automator, AIOSEO, Universally, Duplicator, Reviews Feed, OptinMonster, MonsterInsights, ActiveLayer. Oddly (probably a bug), also Contact Form 7, Ninja Forms, and Pirate Forms. They can also pull WPForms addons and WPForms Pro from their own servers. These servers are not moderated and could be used to push malicious code—which ought to be expected, given their track record. Extra context: Awesome Motive is employing and has hired WordPress Plugins Team members.7:03 PM · Aug 9, 2026!function(options){var element=document.getElementById(options.targetId);if(!element)return;var cached=document.querySelector('[data-timezone]');var timeZone=cached&&cached.dataset.timezone||Intl.DateTimeFormat().resolvedOptions().timeZone;element.dataset.timezone=timeZone;element.textContent=(function formatFullTimestamp({ timestamp, lang = "en", timeZone }) { const date = new Date(timestamp); let zone = timeZone; if (zone) try { new Intl.DateTimeFormat("en", { timeZone: zone }).format(); } catch { zone = "UTC"; } return `${new Intl.DateTimeFormat(lang, { hour: "numeric", minute: "2-digit", timeZone: zone }).format(date)} · ${new Intl.DateTimeFormat(lang, { month: "short", day: "numeric", year: "numeric", timeZone: zone }).format(date)}`; })({timestamp:options.timestamp,lang:options.lang,timeZone:timeZone})}({"lang":"en","targetId":"_R_rhpilid4j6_","timestamp":1786302234000});4.1KViews655122Katie Keith@KatieKeithBarn22hI think it’s a bit unfair to call this a backdoor. It doesn’t give them full access to your site. I asked my Claude to analyze the file you mentioned, along with the rest of the setup wizard code in 2.0.0.2. It only lets them install from a fixed list of .org plugins, and they Show more115341GÅRDSTEN@gardstense4hThanks for letting us know, never liked that plugin anyway, hope you don`t have similar news about FluentForms since that is one I really like and use.2390kc@yhyhyh720034hWhat? Why would they install Contact Form 7, Ninja Forms then? I recall that the author of CF7 is Japanese.11514Log in or sign up for XSee what’s happening and join the conversation
Syed Balkhi (Awesome Motive) put a backdoor in WPForms Lite three weeks ago in version 2.0.0. The plugin runs on over 5 million sites.
The file: wpforms-lite/src/SetupWizard/Bridge.php.
What it does: It takes over your browser and opens their app on WPForms' servers. It hands
The story, first surfaced via the Hacker News community, has drawn significant attention among security researchers and practitioners. Details continue to develop; see the original report at twitter.com for the full account.
This article was aggregated automatically by CyberWire Daily's newsfeed engine. Original reporting: twitter.com.
