Unknown Formidable Forms vulnerabilities
4 known vulnerabilities affecting unknown/formidable_forms.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-9768MEDIUMCVSS 4.8fixed in 6.14.12024-11-21
CVE-2024-9768 [MEDIUM] CWE-79 CVE-2024-9768: The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settin
The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd
CVE-2023-1405HIGHCVSS 7.5fixed in 6.22024-01-16
CVE-2023-1405 [HIGH] CWE-502 CVE-2023-1405: The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymou
The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
cvelistv5nvd
CVE-2023-2877HIGHCVSS 8.8fixed in 6.3.12023-06-27
CVE-2023-2877 [HIGH] CWE-863 CVE-2023-2877: The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validat
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Cod
cvelistv5nvd
CVE-2023-0816MEDIUMCVSS 6.5fixed in 6.12023-03-27
CVE-2023-0816 [MEDIUM] CWE-290 CVE-2023-0816: The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to deter
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
cvelistv5nvd