Vulnerability Description
The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those actions in order to delete or view logs, modify forms or modify plugin settings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dcooperman | Magicform | <= 1.6.2 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/browser/magicform/trunk/admin/admin-menu.phpPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/aa3497ae-7f3a-4e67-ad7Third Party Advisory
FAQ
What is CVE-2025-0939?
CVE-2025-0939 is a vulnerability with a CVSS score of 6.3 (MEDIUM). The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This mak...
How severe is CVE-2025-0939?
CVE-2025-0939 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-0939?
Check the references section above for vendor advisories and patch information. Affected products include: Dcooperman Magicform.