Unknown Formidable Forms vulnerabilities

4 known vulnerabilities affecting unknown/formidable_forms.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-9768MEDIUMCVSS 4.8fixed in 6.14.12024-11-21
CVE-2024-9768 [MEDIUM] CWE-79 CVE-2024-9768: The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settin The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd
CVE-2023-1405HIGHCVSS 7.5fixed in 6.22024-01-16
CVE-2023-1405 [HIGH] CWE-502 CVE-2023-1405: The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymou The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
cvelistv5nvd
CVE-2023-2877HIGHCVSS 8.8fixed in 6.3.12023-06-27
CVE-2023-2877 [HIGH] CWE-863 CVE-2023-2877: The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validat The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Cod
cvelistv5nvd
CVE-2023-0816MEDIUMCVSS 6.5fixed in 6.12023-03-27
CVE-2023-0816 [MEDIUM] CWE-290 CVE-2023-0816: The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to deter The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
cvelistv5nvd