Another top WordPress plugin hacked to allow account takeover – stay safe with these tips
- Experts find a way to trick Forminator into deleting a core WordPress file
- This process would trigger the site’s setup, where hackers can take it over
- A patch is available, and users are advised to apply it
A popular WordPress plugin active on hundreds of thousands of websites was found to be carrying a high-severity vulnerability which could allow threat actors to fully take over compromised websites.
Forminator is a website builder plugin which allows WordPress operators to add custom contact, feedback, quizzes, surveys, polls, and payment forms. Everything is drag-and-drop and thus user-friendly, and plays well with many other plugins.
Recently, a security researcher with the alias ‘Phat RiO – BlueRock’ found the plugin had insufficient validation and sanitation of form field input vulnerability, as well as an unsafe file deletion logic. It could be abused to insert a custom file into any field, which would (after a few steps) force Forminator into deleting the core WordPress file. As a result, the entire website enters the “setup” stage, where the attacker can take it over.
How to stay safe
“Deleting wp-config.php forces the site into a setup state, allowing an attacker to initiate a site takeover by connecting it to a database under their control,” noted experts at Wordfence, a WordPress security project.
The vulnerability is tracked as CVE-2025-6463, and has a severity score of 8.8/10 – high. All versions up to 1.44.2 are vulnerable. As per WordPress.org data, there are more than 600,000 active websites using this plugin, making the attack surface rather large.
The first clean version is 1.44.3, and the plugin’s vendors, WPMU DEV, is urging all users to apply it as soon as possible. BleepingComputer says since the patch was released, the plugin was downloaded 200,000 times, “but it is unclear how many are currently vulnerable to exploitation”.
To mitigate the risk of attack, website admins should upgrade their Forminator plugin to the newest version, or disable and delete the plugin altogether. Generally speaking, WordPress as a platform is considered safe, with various plugins and themes being the weakest link in this security chain.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
That being said, WordPress users are advised to only keep those plugins and themes that they’re using, ensuring these are updated regularly, while disabling and deleting all others.
You might also like
Experts find a way to trick Forminator into deleting a core WordPress file This process would trigger the site’s setup, where hackers can take it over A patch is available, and users are advised to apply it A popular WordPress plugin active on hundreds of thousands of websites was found…
Recent Posts
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
- Cyberdecks used to look like little laptops, but now they’re getting more personal
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023