Impact
This vulnerability is a Path Traversal flaw (CWE‑22) that permits an attacker to construct a request to the Forminator plugin and download any file located on the server’s filesystem. The flaw enables the retrieval of files located outside the intended directory, potentially exposing confidential data such as configuration files or credentials.
Affected Systems
All WordPress sites running the Forminator plugin from WPMU DEV – Your All‑In‑One WordPress Platform, versions up to and including 1.55.0.2. Any installation of this plugin, regardless of the WordPress core or other plug‑in configuration, is affected.
Risk and Exploitability
The CVSS score of 7.5 classifies while the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalogue, so no confirmed exploitation is known. Exploitation would involve a simple crafted HTTP request to a file‑download endpoint, and based on the description, it is inferred that no special privileges or authentication appear to be required.
OpenCVE Enrichment