Skip to main content

CVE-2025-7638: Forminator Forms WordPress Plugin SQLI Flaw

CVE-2025-7638 is a time-based SQL injection vulnerability in Forminator Forms WordPress plugin affecting versions up to 1.45.0. Attackers with admin access can extract sensitive database information. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-7638 Overview

CVE-2025-7638 is a time-based SQL injection vulnerability in the Forminator Forms plugin for WordPress. The flaw affects the Contact Form, Payment Form & Custom Form Builder plugin in all versions up to and including 1.45.0. The vulnerability resides in the order_by parameter, which is not properly escaped and lacks sufficient statement preparation. Authenticated attackers with Administrator-level access or above can inject additional SQL statements into existing queries to extract sensitive data from the database. The issue is classified under [CWE-89] (Improper Neutralization of Special Elements used in an SQL Command).

Critical Impact

Authenticated administrators can execute arbitrary SQL against the WordPress database, exposing credentials, form submissions, and other sensitive stored data.

Affected Products

  • Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress
  • All plugin versions up to and including 1.45.0
  • WordPress sites where Administrator-level accounts are accessible to untrusted parties

Discovery Timeline

  • 2025-07-18 - CVE-2025-7638 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7638

Vulnerability Analysis

The vulnerability exists in the Forminator plugin's form entry model, specifically in code responsible for retrieving stored form submissions. The order_by parameter is interpolated into an SQL query without adequate escaping or use of prepared statement placeholders. Attackers can supply crafted input that alters the structure of the query. Because the injection point is an ORDER BY clause, direct data extraction through UNION selects is not straightforward. Attackers instead use time-based techniques, wrapping payloads in functions such as SLEEP() or BENCHMARK() to infer data through observed response delays. Successful exploitation yields read access to any table the WordPress database user can reach, including wp_users password hashes and form submission records containing personally identifiable information. Refer to the WordPress Forminator Class Code for the affected implementation.

Root Cause

The root cause is insufficient input validation combined with insecure query construction. The plugin concatenates the attacker-controlled order_by value directly into the SQL statement rather than binding it via wpdb->prepare() with a strict allowlist of column names. WordPress prepare() placeholders do not support identifier binding, so developers must explicitly validate ORDER BY values against a fixed list.

Attack Vector

Exploitation requires Administrator-level authentication on the target WordPress site. The attacker sends a request that reaches the vulnerable form entry retrieval flow and passes a malicious order_by value containing SQL time-delay payloads. The database evaluates the injected expression, and the attacker measures response latency to enumerate data character by character. The high privilege requirement narrows the practical threat to insider abuse, compromised administrator accounts, or multi-admin environments where lateral privilege boundaries matter.

No verified public exploit code is available. See the Wordfence Vulnerability Report for additional detail.

Detection Methods for CVE-2025-7638

Indicators of Compromise

  • HTTP requests to Forminator administrative endpoints containing order_by values with SQL keywords such as SLEEP, BENCHMARK, IF(, or comment sequences like -- and /*.
  • WordPress requests from administrator sessions that produce abnormally long response times against form entry listing pages.
  • Database slow-query log entries referencing wp_frmt_form_entry or related Forminator tables with unexpected ORDER BY clauses.

Detection Strategies

  • Enable and review WordPress debug and MySQL general query logs to spot injected ORDER BY payloads from Forminator queries.
  • Deploy a web application firewall rule that inspects the order_by parameter on Forminator admin AJAX and REST endpoints for SQL metacharacters.
  • Correlate administrator authentication events with subsequent long-duration requests to Forminator entry views.

Monitoring Recommendations

  • Alert on repeated administrator requests that trigger MySQL execution times exceeding baseline thresholds.
  • Monitor changes to WordPress administrator accounts, including new admin creations and password resets, that could precede exploitation.
  • Track outbound data volumes from the web tier for signs of blind extraction over extended sessions.

How to Mitigate CVE-2025-7638

Immediate Actions Required

  • Update the Forminator plugin to a version later than 1.45.0 as soon as a patched release is available from the vendor.
  • Audit WordPress administrator accounts, remove unused ones, and rotate credentials for any accounts that may have been shared or exposed.
  • Enforce multi-factor authentication for all Administrator-level users to reduce the risk of account takeover.

Patch Information

The vendor advisory referenced by Wordfence identifies all versions up to and including 1.45.0 as vulnerable. Site owners should upgrade to the latest Forminator release that addresses the order_by sanitization issue. Verify the fix by reviewing the plugin changelog for references to CVE-2025-7638 or SQL injection remediation before deployment.

Workarounds

  • Restrict access to the WordPress administrative interface by IP allowlist at the web server or WAF layer until patching is complete.
  • Apply a virtual patch through a WAF that blocks non-alphanumeric characters in the order_by parameter for Forminator endpoints.
  • Reduce the WordPress database user's privileges to the minimum required, avoiding FILE or cross-database access that could amplify injection impact.
bash
# Example WAF rule concept blocking suspicious order_by values
# ModSecurity-style pseudo rule
SecRule ARGS:order_by "@rx (?i)(sleep|benchmark|union|select|--|/\*)" \
  "id:1007638,phase:2,deny,status:403,msg:'Forminator order_by SQLi attempt (CVE-2025-7638)'"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.