WPForms Lite Accused Of Adding Backdoor. I Tested It And Was Surprised

Aug 11, 2026 04:03 PM - 1 hour ago 3

A station connected X posted by Sybre Waaijer (publisher of The SEO Framework plugin) precocious stirred up a statement astir the WPForms Lite WordPress plugin, alleging that it installs a backdoor connected user’s websites. Some WordPress users work together that thing different whitethorn beryllium going connected while others stay unconvinced.

The National Institute of Standards and Technology (NIST) defines a backdoor as:

“An undocumented measurement of gaining entree to machine system. A backdoor is simply a imaginable information risk.”

The Claim That WPForms Inserts A Backdoor

Sybre Waaijer posted connected X that a caller update to Awesome Motive’s WPForms Lite had inserted a backdoor into the plugin.

The declare is that WP Forms contains an onboarding wizard that walks a personification done the configuration steps. The configuration wizard triggers is alleged to rumor a one-hour token that provides administrative entree to the user’s website without first asking the personification for support aliases making it known that this is happening. According Waaijer, this entree level enables Awesome Motive to do things for illustration instal and activate plugins.

Waaijer tweeted:

“Syed Balkhi (Awesome Motive) put a backdoor successful WPForms Lite 3 weeks agone successful type 2.0.0. The plugin runs connected complete 5 cardinal sites.

The file: wpforms-lite/src/SetupWizard/Bridge.php.

What it does:
It takes complete your browser and opens their app connected WPForms’ servers. It hands that app a one-hour login token for your site. Their app tin past enactment connected your behalf connected your site.

What they tin do pinch it:
Their app tin instal and activate plugins. It tin besides move connected a move that starts sending your shape submissions to WPForms’ servers. The plugin ne'er asks first and ne'er warns you.

When it runs:
It kicks successful automatically connected a caller instal during setup, only for administrators. You won’t get a notice. The token expires astatine the extremity of setup, aliases aft an hour.

What they tin install:
Thirteen plugins from WordPress dot org: WP Mail SMTP, WPConsent, Uncanny Automator, AIOSEO, Universally, Duplicator, Reviews Feed, OptinMonster, MonsterInsights, ActiveLayer. Oddly (probably a bug), besides Contact Form 7, Ninja Forms, and Pirate Forms.

They tin besides propulsion WPForms addons and WPForms Pro from their ain servers. These servers are not moderated and could beryllium utilized to push malicious code—which ought to beryllium expected, fixed their way record.”

Pushback From WordPress Community

One personification responded that Awesome Motive is simply a trusted plugin developer and that this is thing Waaijer should beryllium discussing privately pinch them.

@BuildInBits tweeted:

“Awesome Motive has tons of plugins, and they are trusted plugins. For a decade, they person known really to do the activity very well, and they are already connected it. Your look is simply a small unfair to spell nationalist for illustration this.”

Awesome Motive Is A Competitor To Waaijer

Waaijer’s consequence to @BuildInBitsse noted that Awesome Motive is simply a competitor, arsenic some nutrient an SEO plugin. Awesome Motive publishes All In One SEO (AIOSEO) plugin which straight competes pinch Waaijer’s The SEO Framework.

Waaijer’s response:

“They deliberately built a 2nd transmission of admin powerfulness and dressed the .org zip up arsenic Open Source while the existent convention and the package URLs unrecorded connected their side.

For complete a decade, WPBeginner has been the friends look of that instrumentality — tutorials that ever someway extremity astatine their ain stack. Not a blog. A funnel.

For years, they’ve been cross-installing their plugins and deactivating their competitors’, including mine. I don’t respect them; they earned this.”

Is It Really A Backdoor?

A backdoor is codification that grants entree by circumventing a site’s normal authentication and authorization checks, mostly without the tract owner’s knowledge, aliases arsenic the NIST describes it,  it’s an “undocumented measurement of gaining entree to machine system.”

X personification @marckranat challenged Waaijer’s backdoor characterization of the plugin’s onboarding functionality.

They wrote:

“”Backdoor” is doing a batch of rhetorical activity here. It isn’t successful the accepted sense. There’s nary vendor-initiated entree path, nary auth bypass, and nary hidden listener. It requires a logged-in administrator to really trigger the wizard.”

@marckranat has a constituent that the vendor, Awesome Motive, apt cannot independently initiate entree to a website that installs the plugin. That’s not what is happening erstwhile a personification installs a the plugin.

I Installed WPForms Lite. This Is What Happened

I already usage the WPForms Lite plugin connected 1 of my sites and decided to trial it connected different one. I installed it and was presented pinch a configuration wizard screen. I don’t callback clicking into the screen. Maybe that happened but I don’t callback that happening.

Screenshot of Welcome to WPForms page:

Screenshot showing a header that says Welcome to WPForms, immoderate promotional matter and a fastener pinch the words "Set Up My Forms" connected it.

 

Now, here’s the thing, I thought I was still connected my website. But I was already connected different site.

Screenshot Of URL of Welcome Screen

//wpformsapi.com/setupwizard/v1/welcome

This is the adjacent screen:

Screenshot Of Configuration Wizard

A web page pinch a header that says Make Sure Form Emails Get Delivered, a mean size vertebrate icon pinch the words WP Mail SMTP by WPForms, and an orangish Install and Continue fastener and a importantly smaller nexus beneath it that says Skip This Step

I really clicked Install and Continue, conjecture I wasn’t paying attraction arsenic I thought this was a portion of the installation process. That’s connected me, right?

Screenshot Of Select Your Features Screen

The screenshot shows that “AI Form Generation” and the “Privacy Compliance” boxes are ticked for installation and cannot beryllium opted out. The “Accept Payments” container tin beryllium opted retired of. At the bottommost of the surface is simply a announcement that the free “WPConsent” plugin will beryllium installed, nary measurement to opt retired of that, either.

The Last Screen Of Setup Wizard

Screenshot of plugin web page notifying they detected a competing shape plugin and asking if the personification would for illustration to import existing forms.

Screenshot Showing Three Plugins Installed

As you tin see, WP Mail SMTP, WPConsent, and WPForms Lite were each installed. For astir of these screens I had nary thought that I was nary longer connected my site. I don’t callback seeing immoderate notification that I was going to time off my site. I uninstalled the plugin and tried to reproduce the aforesaid workflow but it didn’t hap again.

So Is It A Backdoor?

Sybre Waaijer says that the plugin drops a token that expires wrong an hr that enables WPForms Lite to make changes connected the site, astir apt for importing information from different interaction forms and besides for installing those different plugins. That’s not a malicious purpose, it’s a reasonable and rather communal pinch plugins. But it did consciousness weird to extremity up connected different website without moreover knowing it.

Still, is it normal for a plugin’s setup wizard to return the personification to different website? What do you person to say?

Featured Image by Shutterstock/Luis Molinero

Category News WordPress
Follow Us On Google
More