• News/
  • https://www.bleepingcomputer.com/news/security/forminator-plugin-flaw-exposes-wordpress-sites-to-takeover-attacks/

Forminator plugin flaw exposes WordPress sites to takeover attacks

BleepingComputer
·
Bill Toulas
·
Published Jul 2, 2025
·
Updated

The Forminator plugin for WordPress is vulnerable to an unauthenticated arbitrary file deletion flaw that could enable full site takeover attacks. The security issue is tracked as CVE-2025-6463 and has a high-severity impact (CVSS 8.8 score). It impacts all versions of Forminator up to 1.44.2. Forminator Forms is a plugin developed by WPMU DEV. It offers a flexible, visual drag‑and‑drop builder to help users create and embed a wide range of form-based content on WordPress sites. According to statistics from WordPress.org, the plugin is currently active on more than 600,000 websites. The vulnerability stems from insufficient validation and sanitization of form field input and unsafe file deletion logic in the plugin’s backend code. When a user submits a form, the ‘save_entry_fields()’ function saves all field values, including file paths, without checking if those fields are supposed to handle files. An attacker could exploit this behavior to insert a crafted file array into any field, including text fields, mimicking an uploaded file with a custom path that points to a critical file, such as ‘/var/www/html/wp-config.php.’ When the admin deletes this or when the plugin auto-deletes old submissions (as configured), Forminator wipes the core WordPress file, forcing the website to enter a “setup” stage where it’s vulnerable to takeover. “Deleting wp-config.php forces the site into a setup state, allowing an attacker to initiate a site takeover by connecting it to a database unde...

Read full article

Affected Software

1 affected component
WPMU DEV Forminator=1.44.2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a vulnerability in the Forminator plugin for WordPress that could lead to site takeover attacks.

2

What security implications are discussed in the article?

The article highlights an unauthenticated arbitrary file deletion flaw that can allow attackers to gain full control of affected WordPress sites.

3

What products or software are affected by this vulnerability?

The vulnerability affects the WPMU DEV Forminator plugin specifically version 1.44.2.

4

What is the severity level of the vulnerability mentioned?

The vulnerability is rated with a CVSS score of 8, indicating a high-severity impact.

5

How can site administrators protect their WordPress sites from this issue?

Site administrators are advised to update the Forminator plugin to the latest version to mitigate the risk of exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203