CVE-2019-15780 — Deserialization of Untrusted Data in Formidable Form Builder
Severity
9.8CRITICALNVD
EPSS
1.1%
top 21.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 24
Description
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9