MagicForm WordPress Plugin Missing Authorization Vulnerability

Vulnerability

A vulnerability exists in the MagicForm plugin for WordPress, in all versions through 1.6.2, due to a lack of proper capability checks on the plugin's AJAX actions. This flaw allows authenticated attackers with Subscriber-level access and above to access and modify data by invoking these AJAX actions. Exploitation could lead to unauthorized deletion or viewing of logs, modification of forms, or changes to plugin settings.

Impact

Exploitation of this vulnerability could result in unauthorized access to and modification of plugin data, including logs, forms, and settings.

Remediation

No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.9
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.