Impact
This vulnerability is a missing authorization flaw in the WPMU DEV Forminator plugin. It permits users without proper privileges to view, modify, or delete forms, potentially exposing or altering collected data. The weakness is categorized as CWE-862: Missing Authorization and carries a CVSS score of 7.5, indicating a high severity impact on confidentiality, integrity, and availability of the site’s form functions.
Affected Systems
All WordPress installations using the Forminator plugin version 1.57.2 or older are impacted. The affected product list includes every deployment of WPMU DEV Forminator up to and including 1.57.2, regardless of the specific WordPress version. No particular operating system or server configuration is singled out.
Risk and Exploitability
The CVSS score of 7.5 reflects significant risk. Although the EPSS score is not available, the lack of a KEV listing suggests no known widespread exploitation yet, but the flaw remains a serious risk for any site with exposed forms. The likely attack vector, inferred from the description as a “missing authorization” issue, is a remote network-based request to the plugin’s form access endpoints. An attacker can craft or manipulate HTTP requests to exploit the unchecked privilege checks and gain access to any form data or administrative settings within the plugin.
OpenCVE Enrichment