Data Modification Vulnerability in MagicForm Plugin for WordPress
CVE-2025-0939
6.3MEDIUM
Summary
The MagicForm plugin for WordPress contains a significant security flaw due to a lack of capability checks on its AJAX actions, which affects all versions up to and including 1.6.2. This vulnerability allows authenticated users with Subscriber-level permissions or higher to exploit the plugin. Attackers can access and modify sensitive data, enabling them to delete or view logs, alter forms, or adjust plugin settings improperly. Site administrators should take immediate steps to apply available security updates and review user permissions to mitigate potential risks.
Affected Version(s)
MagicForm * <= 1.6.2
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lucio Sá