arrowProducts
Glide CMS imageGlide CMS image
Glide CMSarrow
The AI-boosted headless CMS for media, sports and entertainment. MACH architecture gives business freedom, AI gives prompting power.
Glide Go imageGlide Go image
Glide Goarrow
Ready to go enterprise sites for media and large audience projects. Select styles, choose components, add content, Go. Glide CMS, AI, hosting, support, maintenance included.
Glide Nexa imageGlide Nexa image
Glide Nexaarrow
AIP with audience authentication, entitlements, and preference management in one system designed for media and content businesses with engaged audiences.
For your sectorarrowarrow
Media & Entertainment
arrowarrow
Built for any content to thrive, whomever it's for. Get content out faster and do more with it.
Sports & Gaming
arrowarrow
Bring fans closer to their passions and deliver unrivalled audience experiences wherever they are.
Publishing
arrowarrow
Tailored to the unique needs of publishing so you can fully focus on audiences and content success.
Use casesarrowarrow
Technology
arrowarrow
Unlock resources and budget with low-code & no-code solutions to do so much more.
Editorial & Content
arrowarrow
Make content of higher quality quicker, and target it with pinpoint accuracy at the right audiences.
Developers
arrowarrow
MACH architecture lets you kickstart development, leveraging vast native functionality and top-tier support.
Commercial & Marketing
arrowarrow
Speedrun ideas into products, accelerate ROI, convert interest, and own the conversation.
Technology Partnersarrowarrow
Explore Glide's world-class technology partners and integrations.
Solution Partnersarrowarrow
For workflow guidance, SEO, digital transformation, data & analytics, and design, tap into Glide's solution partners and sector experts.
Industry Insightsarrowarrow
News
arrowarrow
News from inside our world, about Glide Publishing Platform, our customers, and other cool things.
Comment
arrowarrow
Insight and comment about the things which make content and publishing better - or sometimes worse.
Expert Guides
arrowarrow
Essential insights and helpful resources from industry veterans, and your gateway to CMS and Glide mastery.
Newsletter
arrowarrow
The Content Aware weekly newsletter, with news and comment every Thursday.
Knowledgearrowarrow
Customer Support
arrowarrow
Learn more about the unrivalled customer support from the team at Glide.
Documentation
arrowarrow
User Guides and Technical Documentation for Glide Publishing Platform headless CMS, Glide Go, and Glide Nexa.
Developer Experience
arrowarrow
Learn more about using Glide headless CMS, Glide Go, and Glide Nexa identity management.

Latest WordPress plug-in security issue exposes user data

Major exploits identified in a form building plug-in have potentially exposed users to malicious actors

by Rob Corbidge

Published: 14:32, 31 July 2023
Latest WordPress plug-in security issue exposes user data

Hundreds of thousands of websites have been affected by the latest WordPress plug-in security issue, with the exposed personal details of site users at the heart of the security headache.

Popular plug-in Ninja Forms, used to create onsite forms and with over 900,000 active installations, was found to have three distinct vulnerabilities in latest version released to customers. The vulnerabilities, according to Patchstack, could result in actors with malicious intent to achieve "privilege escalation" within the affected site's CMS and steal user data.

Users of the plug-in have been urged to update to the latest version of Ninja Forms, which patches the security issue. Precise information about the nature of the exploits was delayed for a number of weeks after they were discovered in order to give admins time to install a secure update from Ninja Forms.

However, as Bleeping Computer have pointed out, many installs of the plug-in remain without such an update, meaning hundreds of thousands of sites and their associated user data are at risk.

Such WordPress plug-in issues almost certainly aren't avoidable, given the number of sites that run on WP globally. There will always be exploits when a system relies on plug-ins and customisation to make it work for the client. 

The consequent, and constant, maintenance cost is either one publishers must accept in order to eliminate risk to their publishing systems, or they must be able to live with a degree of risk, a risk made more complex as each each WordPress install becomes a unique install over time.