Severe WordPress Plugin Flaw Puts Over 600,000 Sites at Risk of Remote Takeover
ID: 2ab658b8-a607-5c9c-b58b-b12fa40ce971
STIX ID: report--2ab658b8-a607-5c9c-b58b-b12fa40ce971
Feed Name: Cyber Press
A high-severity vulnerability (CVE-2025-6463, CVSS 8.8) in the Forminator WordPress plugin allows unauthenticated attackers to craft form submissions that cause arbitrary server file deletion (including wp-config.php), risking complete site takeover for an estimated 600,000+ sites; the vendor released a patch (1.44.3) that restricts deletions to upload/signature fields, confines deletions to the uploads directory, and sanitizes paths — administrators should update immediately, verify critical files, review submissions, and enable WAF protection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
