Time-Based SQL Injection in WordPress Forminator Plugin by WPMU DEV
CVE-2025-7638

4.9MEDIUM

What is CVE-2025-7638?

The Forminator Forms plugin, essential for creating contact and payment forms in WordPress, is susceptible to a time-based SQL injection due to inadequate escaping of user-supplied parameters in the order_by functionality. This flaw allows authenticated users with Administrator-level privileges and above to manipulate existing SQL queries. By injecting additional SQL statements, attackers can potentially access and extract sensitive data from the database, posing a significant risk to site security. It is crucial for users of this plugin to update to the latest version to mitigate these vulnerabilities.

Affected Version(s)

Forminator Forms – Contact Form, Payment Form & Custom Form Builder * <= 1.45.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chive
.