plugin

Magicform Vulnerabilities

5 known security issues reported for the Magicform WordPress plugin. Most recent disclosed May 28, 2026.

1 critical 1 high 1 medium

Running Magicform on your site? Check whether your installed version is affected.

Scan your site free

MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload

critical

The MagicForm plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 0.1.3. This is due to missing file type validation. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server, which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 0.1.3
Fix:
No patched version reported
Disclosed:
May 28, 2026

CVE-2026-9815 on NVD →

MagicForm - WordPress Form Builder <= 1.6.2 - Missing Authorization

medium

The MagicForm plugin for WordPress is vulnerable to access and modification of data due to a missing capability check on the plugin's AJAX actions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to invoke those actions in order to...

CVSS:
6.3
Affected:
up to 1.6.2
Fix:
No patched version reported
Disclosed:
Jan 31, 2025

CVE-2025-0939 on NVD →

MagicForm [magicform] <= 0.1 (unfixed + closed)

unknown

[en] Reflected Cross-Site Scripting (XSS) vulnerability in Dmytriy.Cooperman MagicForm plugin <= 0.1 versions.

Affected:
up to 0.1
Fix:
No patched version reported
Disclosed:
Mar 20, 2023

CVE-2022-47592 on NVD →

MagicForm <= 0.1 - Cross-Site Scripting

high

The MagicForm plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 0.1
Fix:
No patched version reported
Disclosed:
Jan 13, 2023

CVE-2022-47592 on NVD →

MagicForm [magicform] <= 1.6.2 (unfixed + closed)

unknown
Affected:
up to 1.6.2
Fix:
No patched version reported

CVE-2025-0939 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database