Showing 4 vulnerabilities on this page for formidable_forms

Signals CISA KEV Ransomware Nuclei
strategy11 vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Formidable Forms < 6.14.1 - Admin+ Stored XSS

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

CWE-79Nov 21, 2024
CVSS4.8v3.1EPSS0.418%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

CWE-200Oct 16, 20241 related artifact
CVSS5.3v3.1EPSS1.13%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CWE-79Oct 16, 20241 related artifact
CVSS8.3v3.1EPSS1.03%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress Formidable Forms plugin <= 6.7 - Content Injection vulnerability

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.

CWE-79CWE-80May 17, 2024
CVSS5.3v3.1EPSS0.336%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX