Data Modification Vulnerability in MagicForm Plugin for WordPress
CVE-2025-0939
6.3MEDIUM
What is CVE-2025-0939?
The MagicForm plugin for WordPress contains a significant security flaw due to a lack of capability checks on its AJAX actions, which affects all versions up to and including 1.6.2. This vulnerability allows authenticated users with Subscriber-level permissions or higher to exploit the plugin. Attackers can access and modify sensitive data, enabling them to delete or view logs, alter forms, or adjust plugin settings improperly. Site administrators should take immediate steps to apply available security updates and review user permissions to mitigate potential risks.
Affected Version(s)
MagicForm * <= 1.6.2