Impact
The WordPress Forminator plugin contains an unauthenticated vulnerability that allows an attacker to perform actions without valid credentials. The flaw is classified as CWE‑294, which represents improper credential validation. The CVSS score is 5.3, indicating a moderate level of risk, but the advisory does not enumerate the specific data or functionality that could be compromised by exploitation.
Affected Systems
Affected systems are sites running the WPMU DEV Forminator plugin for WordPress with a version of 1.57.1 or earlier. No other product or vendor was listed as affected. The fix requires updating to at least version 1.57.2.
Risk and Exploitability
The vulnerability poses a moderate risk as reflected by the CVSS score. EPSS information is not available, and the issue is not listed in the CISA KEV catalog. The attack appears to be reachable through the plugin’s web interface and does not need authentication; this inference is based on the description that it is an unauthenticated flaw. Since the exact exploitation outcome is not disclosed, the potential impact remains uncertain.
OpenCVE Enrichment