Impact
An unauthenticated attacker can delete arbitrary content in WordPress sites that have the Forminator plugin installed in version 1.57.3 or earlier. The vulnerability allows the removal of posts, pages, or other content without requiring any user privileges, leading to loss of data and potential disruption of site functionality. The weakness is rooted in missing authentication checks on deletion actions, mapping to CWE‑862.
Affected Systems
The flaw affects sites running the WPMU DEV Forminator plugin at version 1.57.3 or earlier. Users should verify the plugin version and upgrade promptly because the issue is present across all affected releases of that plugin by that vendor.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. Although the EPSS score is not available, the lack of authentication checks suggests that exploitation could be straightforward if the attacker can reach the site. The vulnerability is not currently listed in the CISA KEV catalog, but site owners should treat it as high risk due to potential data loss. Protective measures rely on ensuring only authenticated privileged users can trigger deletion operations.
OpenCVE Enrichment