Another top WordPress plugin hacked to allow account takeover – stay safe with these tips


- Experts find a way to trick Forminator into deleting a core WordPress file
- This process would trigger the site’s setup, where hackers can take it over
- A patch is available, and users are advised to apply it
A popular WordPress plugin active on hundreds of thousands of websites was found to be carrying a high-severity vulnerability which could allow threat actors to fully take over compromised websites.
Forminator is a website builder plugin which allows WordPress operators to add custom contact, feedback, quizzes, surveys, polls, and payment forms. Everything is drag-and-drop and thus user-friendly, and plays well with many other plugins.
Recently, a security researcher with the alias ‘Phat RiO – BlueRock’ found the plugin had insufficient validation and sanitation of form field input vulnerability, as well as an unsafe file deletion logic. It could be abused to insert a custom file into any field, which would (after a few steps) force Forminator into deleting the core WordPress file. As a result, the entire website enters the “setup” stage, where the attacker can take it over.
How to stay safe
“Deleting wp-config.php forces the site into a setup state, allowing an attacker to initiate a site takeover by connecting it to a database under their control,” noted experts at Wordfence, a WordPress security project.
The vulnerability is tracked as CVE-2025-6463, and has a severity score of 8.8/10 – high. All versions up to 1.44.2 are vulnerable. As per WordPress.org data, there are more than 600,000 active websites using this plugin, making the attack surface rather large.
The first clean version is 1.44.3, and the plugin’s vendors, WPMU DEV, is urging all users to apply it as soon as possible. BleepingComputer says since the patch was released, the plugin was downloaded 200,000 times, “but it is unclear how many are currently vulnerable to exploitation”.
To mitigate the risk of attack, website admins should upgrade their Forminator plugin to the newest version, or disable and delete the plugin altogether. Generally speaking, WordPress as a platform is considered safe, with various plugins and themes being the weakest link in this security chain.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
That being said, WordPress users are advised to only keep those plugins and themes that they’re using, ensuring these are updated regularly, while disabling and deleting all others.
You might also like
Experts find a way to trick Forminator into deleting a core WordPress file This process would trigger the site’s setup, where hackers can take it over A patch is available, and users are advised to apply it A popular WordPress plugin active on hundreds of thousands of websites was found…
Recent Posts
- British startup claims to have developed tech that can deliver 65% lossless file compression – but you’ll have to pay big for it
- The White House’s favorite source of pro-Trump news is … the White House’s YouTube channel
- NYT Wordle today — answer and my hints for game #1476, Friday, July 4
- We confirmed Nintendo’s Switch 2 TV dock supports VRR — so why doesn’t it work with Switch 2?
- Chinese vendor launches liquid-cooled mini PC powered by AMD’s most powerful AI processor, with a built-in 400W PSU
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021