Time-Based SQL Injection in WordPress Forminator Plugin by WPMU DEV
CVE-2025-7638
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 July 2025
What is CVE-2025-7638?
The Forminator Forms plugin, essential for creating contact and payment forms in WordPress, is susceptible to a time-based SQL injection due to inadequate escaping of user-supplied parameters in the order_by
functionality. This flaw allows authenticated users with Administrator-level privileges and above to manipulate existing SQL queries. By injecting additional SQL statements, attackers can potentially access and extract sensitive data from the database, posing a significant risk to site security. It is crucial for users of this plugin to update to the latest version to mitigate these vulnerabilities.
Affected Version(s)
Forminator Forms – Contact Form, Payment Form & Custom Form Builder * <= 1.45.0