FormCraft – Form Builder [formcraft-form-builder] < 1.2.8
unknown
[en] Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.
- Affected:
- up to 1.2.8
- Fixed in:
- 1.2.8
- Disclosed:
- Dec 9, 2024
CVE-2023-47823 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 1.2.11
unknown
[en] Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.11
- Disclosed:
- Nov 1, 2024
CVE-2024-43157 on NVD →
FormCraft <= 1.2.10 - Missing Authorization
medium
The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on the 'formcraft_basic_check' and 'formcraft_basic_check_form_page_access' functions in versions up to, and including, 1.2.10. This makes it possible for authenticated attackers, with subscriber-level acces...
- CVSS:
- 4.3
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.11
- Disclosed:
- Aug 7, 2024
CVE-2024-43157 on NVD →
FormCraft <= 1.2.7 - Missing Authorization via formcraft_nag_update
medium
The FormCraft plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the formcraft_nag_update AJAX nopriv_ function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to delay or disable update notifications.
- CVSS:
- 5.3
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Nov 16, 2023
CVE-2023-47823 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 1.2.7
unknown
[en] The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 30, 2023
CVE-2023-3501 on NVD →
FormCraft <= 1.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary w...
- CVSS:
- 4.4
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.7
- Disclosed:
- Aug 2, 2023
CVE-2023-3501 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 3.9.7
unknown
[en] The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected:
- up to 3.9.7
- Fixed in:
- 3.9.7
- Disclosed:
- Jun 27, 2023
CVE-2023-2592 on NVD →
FormCraft Premium <= 3.9.6 - Authenticated(Administrator+) SQL Injection
medium
The FormCraft Premium plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with ad...
- CVSS:
- 6.6
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.6
- Disclosed:
- Jun 5, 2023
CVE-2023-2592 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 1.2.10
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.
- Affected:
- up to 1.2.10
- Fixed in:
- 1.2.10
- Disclosed:
- May 15, 2023
CVE-2023-22717 on NVD →
FormCraft <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fcb shortcode
medium
The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fcb shortcode in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and abo...
- CVSS:
- 6.4
- Affected:
- up to 1.2.9
- Fixed in:
- 1.2.10
- Disclosed:
- Apr 19, 2023
CVE-2023-22717 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 1.2.6
unknown
[en] The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jun 6, 2022
CVE-2022-1647 on NVD →
FormCraft Basic <= 1.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- May 16, 2022
CVE-2022-1647 on NVD →
Formcraft3 <= 3.8.27 - Server Side Request Forgery
critical
The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users
- CVSS:
- 9.1
- Affected:
- up to 3.8.28
- Fixed in:
- 3.8.28
- Disclosed:
- Feb 28, 2022
CVE-2022-0591 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 1.2.2
unknown
[en] The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 16, 2019
CVE-2019-15114 on NVD →
FormCraft – Form Builder [formcraft-form-builder] < 1.2.2
unknown
[en] Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Mar 12, 2019
CVE-2019-5920 on NVD →
FormCraft <= 1.2.1 - Cross-Site Request Forgery
high
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Feb 26, 2019
CVE-2019-15114 on NVD →
FormCraft <= 1.2.1 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
- CVSS:
- 8.8
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Feb 26, 2019
CVE-2019-5920 on NVD →
FormCraft Basic 1.0.5 - SQL Injection via id Parameter
critical
The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
- CVSS:
- 9.8
- Affected:
- 1.0.5 – 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 5, 2017
CVE-2017-13137 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database