
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14782 is an authorization bypass vulnerability in the Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress, affecting all versions up to and including 1.49.1. The flaw exists in the listen_for_csv_export function, which fails to properly verify that a requesting user is authorized to perform the export action. It was published on January 9, 2026, and assigned a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-862 (Missing Authorization): the plugin's listen_for_csv_export function does not perform adequate capability or permission checks before allowing a CSV export of form submission data. An authenticated attacker who has access to the Forminator dashboard — but who should not have export privileges — can trigger this function over the network to download sensitive data. The fix was introduced in the plugin changeset modifying library/class-export.php to enforce proper authorization checks (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker with dashboard access — but without explicit export permissions — to export all form submission data as a CSV file. This data may include personally identifiable information (PII) such as names, email addresses, phone numbers, and payment-related details submitted through contact, payment, or custom forms. The impact is limited to confidentiality (no integrity or availability impact), but the exposure of PII can have significant compliance and privacy consequences for affected site operators (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authentication and access to the Forminator dashboard, which raises the bar for opportunistic attackers (Wordfence).
listen_for_csv_export function in library/class-export.php.listen_for_csv_export without the required authorization checks being enforced.forminator export action parameters) from users who do not normally perform exports.Site administrators should update the Forminator Forms plugin to version 1.49.2 or later, which includes the fix that enforces proper authorization checks in the listen_for_csv_export function. No configuration-based workaround is documented; upgrading is the recommended and only reliable remediation. As an interim measure, administrators can restrict dashboard access to only fully trusted users until the update is applied (Wordfence, WordPress Trac).
Sucuri included CVE-2025-14782 in their January 2026 vulnerability patch roundup, highlighting it as one of several WordPress plugin issues requiring attention (Sucuri Blog). Wordfence, which discovered and disclosed the vulnerability, assigned it a medium severity rating and noted the patch availability in version 1.49.2. No significant broader media coverage or notable researcher commentary beyond standard disclosure channels has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."