CVE-2023-0816

MEDIUM

Formidable Forms WordPress Plugin < 6.1 - IP Address Spoofing via Untrusted Headers

Title source: llm
STIX 2.1

Description

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/a281f63f-e295-4666-8a08-01b23cd5a744

Scores

CVSS v3 6.5
EPSS 0.0050
EPSS Percentile 38.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (1)
strategy11/formidable_form_builder < 6.1
Published Mar 27, 2023
Tracked Since Feb 18, 2026