Logo

WordPress Plugin Bug Puts Small Business Sites at Risk

If your business website runs on WordPress, a newly disclosed security flaw is worth pausing for. Researchers have revealed a critical vulnerability in Forminator Forms, a plugin installed on more than 600,000 websites, that could let an attacker take complete control of a site without even needing a username or password. For small businesses across Gippsland and regional Victoria who rely on their website to take bookings, capture leads, or process customer enquiries, this is exactly the kind of quiet, unglamorous vulnerability that ends up doing real damage.

What actually happened

As reported by The Hacker News, the flaw – tracked as CVE-2026-15748 and rated 9.8 out of 10 in severity – allows an attacker to upload malicious PHP files through the Forminator plugin’s file upload feature. Because the flaw doesn’t require the attacker to be logged in, anyone who finds a vulnerable site can potentially exploit it directly. Once a malicious file is uploaded and executed, the attacker effectively has the same level of control over the website as the site owner does.

Forminator is a popular tool for building contact forms, quote request forms, polls, and quizzes on WordPress sites. It’s the kind of plugin many small businesses install once, set up, and then forget about entirely – which is exactly the problem.

Why this matters for a small business, not just big companies

It’s tempting to read stories like this and assume they only affect large corporations with dedicated IT security teams. In reality, small business websites are often easier targets precisely because nobody is actively watching them. A compromised site can be used to:

  • Redirect your customers to scam or malware pages, damaging trust in your brand
  • Send spam or phishing emails from your domain, potentially getting your domain blacklisted
  • Host malicious files that get flagged by Google, causing your site to be removed from search results or hit with a browser warning
  • Act as an entry point into your wider business systems if your website shares credentials, hosting, or email infrastructure with other tools
  • Quietly steal any customer data submitted through your contact or booking forms

For a local trade business, retailer, clinic, or professional service, even a few days of a defaced or blacklisted website can mean lost bookings, lost sales, and an awkward conversation with customers about why their details might have been exposed.

The real lesson: plugins are a bigger risk than most business owners realise

WordPress itself is generally well maintained and secure. The bigger risk almost always comes from the plugins and themes installed on top of it – and most small business websites are running far more of these than the owner realises, often installed years ago by a web designer who has long since moved on. Every plugin is a piece of software that needs updating, and every outdated plugin is a potential unlocked door.

This particular Forminator vulnerability is a useful case study because it shows how quickly a “set and forget” plugin can become a serious liability. The plugin developer has released a patch, but a patch only protects you if it’s actually applied.

What you should do right now

  • If you know your website uses Forminator Forms, update it to the latest version immediately, or ask whoever manages your website to confirm it’s been updated
  • Don’t assume your web host handles plugin updates automatically – many hosting packages only cover the server, not the plugins running on it
  • Ask your website provider or IT support for a full list of every plugin currently active on your site, including ones that are no longer used
  • Remove or deactivate any plugin that isn’t essential – fewer plugins means a smaller attack surface
  • Check when your WordPress core, theme, and plugins were last updated – if it’s been more than a few months, that’s a red flag

Building better habits for the long term

This won’t be the last plugin vulnerability to make headlines, and it’s unlikely to be the most severe one your business ever encounters. The businesses that come through these events unscathed are the ones with a simple, ongoing maintenance routine rather than those relying on luck.

  • Schedule regular website health checks – monthly is a reasonable minimum for a business-critical site
  • Use a reputable security plugin or monitoring service that alerts you to available updates and suspicious activity
  • Take regular backups of your website and store them somewhere separate from your hosting account, so you can restore quickly if something does go wrong
  • Limit who has admin access to your website, and use strong, unique passwords plus multi-factor authentication for the WordPress login
  • If you use a web developer or agency, clarify in writing whether ongoing plugin updates and security monitoring are included in your arrangement – many businesses assume this is covered when it isn’t

A five-minute check worth doing today

You don’t need to be technical to get a basic sense of your exposure. Log into your WordPress admin dashboard, go to the Plugins section, and look at two things: how many plugins are installed, and whether any are flagged as needing an update. If you don’t have a login, or you’re not sure who does, that in itself is a sign your website’s security is being managed by nobody – which is worth fixing regardless of this particular vulnerability.

Website security rarely feels urgent until the moment it becomes very urgent indeed. A ten-minute plugin update today is a much better use of your time than a weekend spent explaining to customers why your site was serving malware.


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions