Data Modification Vulnerability in MagicForm Plugin for WordPress
CVE-2025-0939
What is CVE-2025-0939?
The MagicForm plugin for WordPress contains a significant security flaw due to a lack of capability checks on its AJAX actions, which affects all versions up to and including 1.6.2. This vulnerability allows authenticated users with Subscriber-level permissions or higher to exploit the plugin. Attackers can access and modify sensitive data, enabling them to delete or view logs, alter forms, or adjust plugin settings improperly. Site administrators should take immediate steps to apply available security updates and review user permissions to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MagicForm * <= 1.6.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved