
Software
600,000 WordPress sites run this form plugin. one bug turns a dropdown into a hacker's backdoor
A file-upload field and a dropdown, sitting on the same form, are all it takes for an unauthenticated attacker to plant PHP code on your site. The fix has existed since July 31 — most sites just haven't installed it.
Priya Nair · 1h ago · 6 min