{"id":30481,"date":"2026-08-25T07:31:19","date_gmt":"2026-08-25T05:31:19","guid":{"rendered":"https:\/\/perseus.de\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/"},"modified":"2026-08-25T16:21:16","modified_gmt":"2026-08-25T14:21:16","slug":"sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins","status":"publish","type":"post","link":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/","title":{"rendered":"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30481\" class=\"elementor elementor-30481 elementor-30371\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dcf4ec4 e-flex e-con-boxed e-con e-parent\" data-id=\"dcf4ec4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1db58c elementor-widget elementor-widget-image\" data-id=\"e1db58c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"200\" src=\"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png\" class=\"attachment-large size-large wp-image-27799\" alt=\"\" srcset=\"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png 1024w, https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-300x75.png 300w, https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-768x192.png 768w, https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025.png 1200w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1258a43 e-flex e-con-boxed e-con e-parent\" data-id=\"1258a43\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2de4e88 e-con-full e-flex e-con e-child\" data-id=\"2de4e88\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4982c80 elementor-widget elementor-widget-text-editor\" data-id=\"4982c80\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h6>24.08.2026<\/h6>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8348bc5 elementor-widget elementor-widget-heading\" data-id=\"8348bc5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Critical vulnerabilities in WordPress plugins:<br \/><br \/>\nForminator Forms and Royal Elementor Addons.<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-eb03842 e-con-full e-flex e-con e-child\" data-id=\"eb03842\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-91d0988 elementor-widget elementor-widget-text-editor\" data-id=\"91d0988\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>  <\/p><p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"147\" data-end=\"603\"><strong data-start=\"147\" data-end=\"603\">Current security vulnerabilities have been discovered in two widely used WordPress plugins. Forminator Forms and Royal Elementor Addons are affected. A vulnerability in Forminator Forms is particularly critical: Under certain conditions, threat actors can execute malicious code on a WordPress website without valid credentials and, in the worst case, take it over completely. The plugin is active on more than 600,000 WordPress websites.<\/strong><\/p><p data-start=\"608\" data-end=\"773\">A security vulnerability was also discovered in Royal Elementor Addons that could allow attackers to misuse a WordPress website to access internal systems.<\/p><p data-start=\"778\" data-end=\"988\" data-is-last-node=\"\"><strong data-start=\"778\" data-end=\"988\" data-is-last-node=\"\">In this article, we give an overview of the two vulnerabilities, explain which versions are affected, and show what measures WordPress website operators should take now.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-ceb0f40 e-flex e-con-boxed e-con e-parent\" data-id=\"ceb0f40\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffbdc12 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"ffbdc12\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e8d5e68 elementor-widget elementor-widget-spacer\" data-id=\"e8d5e68\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c054958 e-flex e-con-boxed e-con e-parent\" data-id=\"c054958\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-aa3e4fa elementor-widget elementor-widget-heading\" data-id=\"aa3e4fa\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"forminator\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">1. Critical vulnerability in Forminator Forms  <\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-42b4f7d e-flex e-con-boxed e-con e-parent\" data-id=\"42b4f7d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-eeaec64 elementor-widget elementor-widget-spacer\" data-id=\"eeaec64\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-02dd0e9 e-flex e-con-boxed e-con e-parent\" data-id=\"02dd0e9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-16d621d e-con-full e-flex e-con e-child\" data-id=\"16d621d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89904c7 elementor-widget elementor-widget-text-editor\" data-id=\"89904c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What happened?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fae461d e-con-full e-flex e-con e-child\" data-id=\"fae461d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0f04793 elementor-widget elementor-widget-text-editor\" data-id=\"0f04793\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The <span style=\"font-weight: 400;\"> critical security vulnerability<\/span><a href=\"https:\/\/www.wordfence.com\/blog\/2026\/08\/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin\/\"> <span style=\"font-weight: 400;\">CVE-2026-15748<\/span><\/a> has been discovered <span style=\"font-weight: 400;\">in the WordPress plugin <\/span><b>Forminator Forms<\/b><span style=\"font-weight: 400;\">. The plugin is used, among other things, to integrate contact forms, surveys and other forms on WordPress websites.<\/span><\/p><p><span style=\"font-weight: 400;\">The vulnerability affects versions up to and including <\/span><b>1.56.1<\/b><span style=\"font-weight: 400;\"> and allows attackers to upload manipulated files to the web server under certain conditions. Particularly critical: <\/span><b>No valid access data<\/b> is required for an attack <span style=\"font-weight: 400;\"> .<\/span><\/p><p><span style=\"font-weight: 400;\">The prerequisite for a successful attack is that a form created with Forminator on the affected website contains both a field for file uploads and a selection field.<\/span><\/p><p data-start=\"1160\" data-end=\"1683\"><strong data-start=\"1181\" data-end=\"1212\">No valid credentials are required<\/strong> for the attack. Instead, the attackers use the vulnerabilities to bypass security mechanisms and take control of a vulnerable WordPress installation. After a successful compromise, <strong data-start=\"1458\" data-end=\"1556\">web shells (programs that give attackers permanent remote access to the server)<\/strong> or other backdoors can be installed, websites can be manipulated, malware can be spread or confidential data can be stolen.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54c68ef e-flex e-con-boxed e-con e-parent\" data-id=\"54c68ef\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-96849ac elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"96849ac\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-174b215 e-flex e-con-boxed e-con e-parent\" data-id=\"174b215\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e560a6b e-con-full e-flex e-con e-child\" data-id=\"e560a6b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-013b67e elementor-widget elementor-widget-text-editor\" data-id=\"013b67e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What can I do?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a72ed48 e-con-full e-flex e-con e-child\" data-id=\"a72ed48\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-db8754f elementor-widget elementor-widget-text-editor\" data-id=\"db8754f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">We recommend the following measures to companies and website operators<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><b>:Check whether Forminator Forms is installed on your WordPress website<\/b><span style=\"font-weight: 400;\"> and which version is used.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Update the plug-in immediately<\/b> <span style=\"font-weight: 400;\">if version 1.56.1 or earlier is installed. The vulnerability has been fixed with <\/span><b>version 1.56.2<\/b><span style=\"font-weight: 400;\">. If possible, install the latest version available.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>As a precaution, check the WordPress installation for suspicious changes<\/b><span style=\"font-weight: 400;\">, especially unknown files, new administrator users, or unexpected changes to existing user accounts.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Check the web server&#8217;s logs for<\/b><span style=\"font-weight: 400;\"> unusual file uploads and suspicious accesses.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>If there are indications of a compromise<\/b><span style=\"font-weight: 400;\">, the incident should be investigated more closely. A security update alone does not remove malware or backdoors that have already been infiltrated.<\/span><\/li><\/ol><p> <\/p><p><span style=\"font-weight: 400;\">Further information on the vulnerability can be found at<\/span><a href=\"https:\/\/www.wordfence.com\/blog\/2026\/08\/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin\/\"> <span style=\"font-weight: 400;\">Wordfence<\/span><\/a><span style=\"font-weight: 400;\"> as well as at<\/span><a href=\"https:\/\/www.all-about-security.de\/forminator-forms-luecke-beim-datei-upload-betrifft-ueber-600-000-wordpress-seiten\/\"> <span style=\"font-weight: 400;\">All About Security<\/span><\/a><span style=\"font-weight: 400;\">. <\/span> <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54465d1 e-flex e-con-boxed e-con e-parent\" data-id=\"54465d1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d02be9e elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d02be9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-990ff39 e-flex e-con-boxed e-con e-parent\" data-id=\"990ff39\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dd34598 elementor-widget elementor-widget-spacer\" data-id=\"dd34598\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d27064c elementor-widget elementor-widget-heading\" data-id=\"d27064c\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"royal\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">2. Vulnerability in Royal Elementor Addons<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e8dfb65 elementor-widget elementor-widget-spacer\" data-id=\"e8dfb65\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c28550e e-flex e-con-boxed e-con e-parent\" data-id=\"c28550e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-b5ac00b e-con-full e-flex e-con e-child\" data-id=\"b5ac00b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4467aca elementor-widget elementor-widget-text-editor\" data-id=\"4467aca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What happened?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-990ca5f e-con-full e-flex e-con e-child\" data-id=\"990ca5f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56e453f elementor-widget elementor-widget-text-editor\" data-id=\"56e453f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>A security vulnerability was <span style=\"font-weight: 400;\">also discovered in the WordPress plugin <\/span><b>Royal Elementor Addons<\/b><span style=\"font-weight: 400;\">. According<\/span> to GitHub, the <a href=\"https:\/\/github.com\/advisories\/GHSA-mgg8-m984-r93c\"> <span style=\"font-weight: 400;\">CVE-2026-17123<\/span><\/a> vulnerability <span style=\"font-weight: 400;\"> affects versions up to and including <\/span><b>1.7.1064<\/b><span style=\"font-weight: 400;\"> and was <\/span><span style=\"font-weight: 400;\"> rated &#8220;high&#8221;<\/span> with a <b>CVSS score of 8.8 out of 10 points<\/b>.<\/p><p><span style=\"font-weight: 400;\">Unlike the vulnerability in Forminator Forms, an attacker already needs a WordPress user account with at least contributor or employee rights. However, if criminals have already gained access to a WordPress website \u2013 for example, by exploiting the vulnerability in Forminator Forms described above \u2013 they may be able to create a user account with the necessary rights and then exploit the vulnerability in Royal Elementor Addons. In this way, several vulnerabilities can be chained together.<\/span><\/p><p><span style=\"font-weight: 400;\"><strong>Note:<\/strong> Even already known and not yet closed WordPress vulnerabilities continue to be exploited by criminals. We have already pointed out corresponding attack possibilities and the use of webshells as a permanent backdoor in our danger warning for WP2Shell.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a2790c7 e-flex e-con-boxed e-con e-parent\" data-id=\"a2790c7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d4feb2c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d4feb2c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7faf510 e-flex e-con-boxed e-con e-parent\" data-id=\"7faf510\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-9a087a2 e-con-full e-flex e-con e-child\" data-id=\"9a087a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4a4eba5 elementor-widget elementor-widget-text-editor\" data-id=\"4a4eba5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>How can the vulnerability be exploited?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f63aea7 e-con-full e-flex e-con e-child\" data-id=\"f63aea7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e249ee4 elementor-widget elementor-widget-text-editor\" data-id=\"e249ee4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The vulnerability is a <\/span><b>so-called Server-Side Request Forgery (SSRF).<\/b><span style=\"font-weight: 400;\"> Put simply, an attacker can trick the affected web server into sending requests to other systems on its behalf.<\/span><\/p><p><span style=\"font-weight: 400;\">As a result, the WordPress website could <\/span> be misused <b>as a starting point for access to internal systems and services<\/b><span style=\"font-weight: 400;\"> that are normally not directly accessible from the Internet. In this way, attackers could request or change internal information.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4e3ed27 e-flex e-con-boxed e-con e-parent\" data-id=\"4e3ed27\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-397d105 e-con-full e-flex e-con e-child\" data-id=\"397d105\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6c3b879 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"6c3b879\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-8cb2db8 e-flex e-con-boxed e-con e-parent\" data-id=\"8cb2db8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-fbbec3e e-con-full e-flex e-con e-child\" data-id=\"fbbec3e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-e6d3e3c e-con-full e-flex e-con e-child\" data-id=\"e6d3e3c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1f75a8b elementor-widget elementor-widget-text-editor\" data-id=\"1f75a8b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What can I do?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1433fc2 e-con-full e-flex e-con e-child\" data-id=\"1433fc2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9707813 elementor-widget elementor-widget-text-editor\" data-id=\"9707813\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">We recommend the following measures to companies and website operators:<\/span><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Check if Royal Elementor Addons is installed on your WordPress website<\/b><span style=\"font-weight: 400;\"> and which version is being used.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Update the WordPress CMS to the latest available version<\/b> <span style=\"font-weight: 400;\">to prevent vulnerability chaining via WP2Shell or XSS2Shell<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Check with the manufacturer whether an updated version is available<\/b> <span style=\"font-weight: 400;\">in which the vulnerability has been fixed. Currently, the<\/span><a href=\"https:\/\/github.com\/advisories\/GHSA-mgg8-m984-r93c\"> <span style=\"font-weight: 400;\">GitHub Security Advisory<\/span><\/a> does <span style=\"font-weight: 400;\"> not yet show a specific patched version.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Check the existing WordPress user accounts and their permissions.<\/b><span style=\"font-weight: 400;\"> Remove accounts that are no longer needed and only assign the rights that are actually required.<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>If you suspect an attack, check web server and WordPress logs<\/b><span style=\"font-weight: 400;\"> for unusual activity and suspicious outbound connections.<\/span><\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1ea7e9a e-flex e-con-boxed e-con e-parent\" data-id=\"1ea7e9a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-7644ba2 e-con-full e-flex e-con e-child\" data-id=\"7644ba2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f33a99d elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"f33a99d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4ea0526 e-flex e-con-boxed e-con e-parent\" data-id=\"4ea0526\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-26e206a elementor-widget elementor-widget-text-editor\" data-id=\"26e206a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">The current vulnerabilities show once again that not only WordPress itself, but also <\/span><b>installed plugins need to be checked and updated regularly<\/b><span style=\"font-weight: 400;\">. Companies should therefore check which extensions are used on their WordPress websites, remove unnecessary plug-ins and install available security updates as soon as possible. <\/span><\/p><p><span style=\"font-weight: 400;\">Another note: <\/span><b>If possible, enable automatic updates for trusted WordPress plugins<\/b> <span style=\"font-weight: 400;\">so that important security updates are installed promptly. <\/span><\/p><h4><b>In<\/b><\/h4><p><span style=\"font-weight: 400;\">our current incident response cases, we are increasingly observing attacks on WordPress websites in which known vulnerabilities in the CMS or plug-ins are exploited. The consequences range from the complete takeover of the website and the theft of access data to the theft of sensitive customer data. Often, outdated systems that are not updated in time are the cause.<\/span><\/p><p><span style=\"font-weight: 400;\">We therefore recommend consistent patch management for WordPress and all plugins used. In addition, a web application firewall (WAF) can help to detect and block attack attempts at an early stage.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-8530d6c e-flex e-con-boxed e-con e-parent\" data-id=\"8530d6c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3bbb54c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"3bbb54c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f2d97c9 elementor-widget elementor-widget-text-editor\" data-id=\"f2d97c9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><i>Do you want to stay informed about current threats and security vulnerabilities?<\/i><\/p><p><i>Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.<\/i><\/p><p><b>Sources &#038; Further Information<\/b><\/p><p> <\/p><p><em><strong>Forminator Forms &#8211; CVE-2026-15748<\/strong><\/em><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><em><strong>Wordfence \u2013<a href=\"https:\/\/www.wordfence.com\/blog\/2026\/08\/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin\/?utm_source=chatgpt.com\"> <\/a><\/strong><\/em><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><em><strong>Vulnerability Intelligence Analysis https:\/\/www.wordfence.com\/blog\/2026\/08\/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin\/ Wordfence \u2013 Vulnerability Intelligence \/ Technical Details<a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/forminator\/forminator-forms-1561-unauthenticated-arbitrary-file-upload-via-forged-upload-field-configuration?utm_source=chatgpt.com\"> https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/forminator\/forminator-forms-1561-unauthenticated-arbitrary-file-upload-via-forged-upload-field-configuration<\/a><\/strong><\/em><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><em><strong>Heise Security \u2013 Forminator Forms<a href=\"https:\/\/www.heise.de\/news\/WordPress-Plug-in-Forminator-Forms-Kritische-Luecke-erlaubt-Codeschmuggel-11416793.html\"> https:\/\/www.heise.de\/news\/WordPress-Plug-in-Forminator-Forms-Kritische-Luecke-erlaubt-Codeschmuggel-11416793.html<\/a><\/strong><\/em><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><em><strong>All About Security \u2013 Forminator Forms<br\/><a href=\"https:\/\/www.all-about-security.de\/forminator-forms-luecke-beim-datei-upload-betrifft-ueber-600-000-wordpress-seiten\/?utm_source=chatgpt.com\">https:\/\/www.all-about-security.de\/forminator-forms-luecke-beim-datei-upload-betrifft-ueber-600-000-wordpress-seiten\/<\/a><\/strong><\/em><\/li><\/ol><p> <\/p><p><em><strong>Royal Elementor Addons \u2013 CVE-2026-17123<\/strong><\/em><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><em><strong>GitHub Security Advisory \u2013 current vulnerability<br\/><a href=\"https:\/\/github.com\/advisories\/GHSA-mgg8-m984-r93c?utm_source=chatgpt.com\"> https:\/\/github.com\/advisories\/GHSA-mgg8-m984-r93c<\/a><\/strong><\/em><\/li><\/ol><p> <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9f86355 e-flex e-con-boxed e-con e-parent\" data-id=\"9f86355\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dd90633 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"dd90633\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Critical security vulnerabilities in the WordPress plugins Forminator Forms and Royal Elementor Addons endanger numerous websites. Find out which versions are affected and which measures are important now.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[64],"tags":[],"class_list":["post-30481","post","type-post","status-publish","format-standard","hentry","category-hazard-warning"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins - Perseus Technologies<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins - Perseus Technologies\" \/>\n<meta property=\"og:description\" content=\"Critical security vulnerabilities in the WordPress plugins Forminator Forms and Royal Elementor Addons endanger numerous websites. Find out which versions are affected and which measures are important now.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/\" \/>\n<meta property=\"og:site_name\" content=\"Perseus Technologies\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-25T05:31:19+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-25T14:21:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"300\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Anastasia Pamoukis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anastasia Pamoukis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/\"},\"author\":{\"name\":\"Anastasia Pamoukis\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#\\\/schema\\\/person\\\/6c87a2feea6439d0ead16c8f0f07e40b\"},\"headline\":\"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins\",\"datePublished\":\"2026-08-25T05:31:19+00:00\",\"dateModified\":\"2026-08-25T14:21:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/\"},\"wordCount\":1043,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png\",\"articleSection\":[\"Hazard warning\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/\",\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/\",\"name\":\"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins - Perseus Technologies\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png\",\"datePublished\":\"2026-08-25T05:31:19+00:00\",\"dateModified\":\"2026-08-25T14:21:16+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#primaryimage\",\"url\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png\",\"contentUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/04\\\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/perseus.de\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/\",\"name\":\"perseus-web.de\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/perseus.de\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#organization\",\"name\":\"perseus-web.de\",\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/PerseusTechnologie_Color-2.png\",\"contentUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/PerseusTechnologie_Color-2.png\",\"width\":536,\"height\":172,\"caption\":\"perseus-web.de\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/#\\\/schema\\\/person\\\/6c87a2feea6439d0ead16c8f0f07e40b\",\"name\":\"Anastasia Pamoukis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"caption\":\"Anastasia Pamoukis\"},\"sameAs\":[\"https:\\\/\\\/perseus.de\"],\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/author\\\/anastasia-pamoukis\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins - Perseus Technologies","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/","og_locale":"en_US","og_type":"article","og_title":"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins - Perseus Technologies","og_description":"Critical security vulnerabilities in the WordPress plugins Forminator Forms and Royal Elementor Addons endanger numerous websites. Find out which versions are affected and which measures are important now.","og_url":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/","og_site_name":"Perseus Technologies","article_published_time":"2026-08-25T05:31:19+00:00","article_modified_time":"2026-08-25T14:21:16+00:00","og_image":[{"width":1200,"height":300,"url":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025.png","type":"image\/png"}],"author":"Anastasia Pamoukis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Anastasia Pamoukis","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#article","isPartOf":{"@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/"},"author":{"name":"Anastasia Pamoukis","@id":"https:\/\/perseus.de\/en\/#\/schema\/person\/6c87a2feea6439d0ead16c8f0f07e40b"},"headline":"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins","datePublished":"2026-08-25T05:31:19+00:00","dateModified":"2026-08-25T14:21:16+00:00","mainEntityOfPage":{"@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/"},"wordCount":1043,"commentCount":0,"publisher":{"@id":"https:\/\/perseus.de\/en\/#organization"},"image":{"@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#primaryimage"},"thumbnailUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png","articleSection":["Hazard warning"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/","url":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/","name":"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins - Perseus Technologies","isPartOf":{"@id":"https:\/\/perseus.de\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#primaryimage"},"image":{"@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#primaryimage"},"thumbnailUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png","datePublished":"2026-08-25T05:31:19+00:00","dateModified":"2026-08-25T14:21:16+00:00","breadcrumb":{"@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#primaryimage","url":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png","contentUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/04\/Gefahrenwarnung-Headerbild-Website-2025-1024x256.png"},{"@type":"BreadcrumbList","@id":"https:\/\/perseus.de\/en\/sicherheitswarnung-kritische-schwachstellen-in-wordpress-plugins\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/perseus.de\/en\/"},{"@type":"ListItem","position":2,"name":"Sicherheitswarnung: Kritische Schwachstellen in WordPress-Plugins"}]},{"@type":"WebSite","@id":"https:\/\/perseus.de\/en\/#website","url":"https:\/\/perseus.de\/en\/","name":"perseus-web.de","description":"","publisher":{"@id":"https:\/\/perseus.de\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/perseus.de\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/perseus.de\/en\/#organization","name":"perseus-web.de","url":"https:\/\/perseus.de\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/perseus.de\/en\/#\/schema\/logo\/image\/","url":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/03\/PerseusTechnologie_Color-2.png","contentUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/03\/PerseusTechnologie_Color-2.png","width":536,"height":172,"caption":"perseus-web.de"},"image":{"@id":"https:\/\/perseus.de\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/perseus.de\/en\/#\/schema\/person\/6c87a2feea6439d0ead16c8f0f07e40b","name":"Anastasia Pamoukis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","caption":"Anastasia Pamoukis"},"sameAs":["https:\/\/perseus.de"],"url":"https:\/\/perseus.de\/en\/author\/anastasia-pamoukis\/"}]}},"_links":{"self":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/comments?post=30481"}],"version-history":[{"count":2,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30481\/revisions"}],"predecessor-version":[{"id":30483,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30481\/revisions\/30483"}],"wp:attachment":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/media?parent=30481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/categories?post=30481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/tags?post=30481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}