strategy11 Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with strategy11 products.
Products
- formidable_forms4 vulnerabilities
- Formidable Form Builder plugin for WordPress3 vulnerabilities
- awp_classifieds1 vulnerability
- Formidable Digital Signatures1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-16230CRITICAL | Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature FieldThe Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissi… CWE-23Aug 11, 2026 | CVSS9.8v3.1 | EPSS0.496% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9768MEDIUM | Formidable Forms < 6.14.1 - Admin+ Stored XSSThe Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). CWE-79Nov 21, 2024 | CVSS4.8v3.1 | EPSS0.418% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-20194MEDIUM | Formidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureThe Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form. | CVSS5.3v3.1 | EPSS1.13% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-20192HIGH | Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site ScriptingThe Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser. | CVSS8.3v3.1 | EPSS1.03% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-23522MEDIUM | WordPress Formidable Forms plugin <= 6.7 - Content Injection vulnerabilityImproper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7. | CVSS5.3v3.1 | EPSS0.336% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-2877HIGH | Formidable Forms < 6.3.1 - Subscriber+ Remote Code ExecutionThe Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution. CWE-863Jun 27, 2023 | CVSS8.8v3.1 | EPSS22.5% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-3254CRITICAL | AWP Classifieds Plugin < 4.3 - Unauthenticated SQLiThe WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection | CVSS9.8v3.1 | EPSS5.16% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |