plugin

Formcraft Form Builder Vulnerabilities

18 known security issues reported for the Formcraft Form Builder WordPress plugin. Most recent disclosed Dec 9, 2024.

2 critical 2 high 6 medium

Running Formcraft Form Builder on your site? Check whether your installed version is affected.

Scan your site free

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.8

unknown

[en] Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.7.

Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Dec 9, 2024

CVE-2023-47823 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.11

unknown

[en] Missing Authorization vulnerability in nCrafts FormCraft allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FormCraft: from n/a through 1.2.10.

Affected:
up to 1.2.11
Fixed in:
1.2.11
Disclosed:
Nov 1, 2024

CVE-2024-43157 on NVD →

FormCraft <= 1.2.10 - Missing Authorization

medium

The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on the 'formcraft_basic_check' and 'formcraft_basic_check_form_page_access' functions in versions up to, and including, 1.2.10. This makes it possible for authenticated attackers, with subscriber-level acces...

CVSS:
4.3
Affected:
up to 1.2.10
Fixed in:
1.2.11
Disclosed:
Aug 7, 2024

CVE-2024-43157 on NVD →

FormCraft <= 1.2.7 - Missing Authorization via formcraft_nag_update

medium

The FormCraft plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the formcraft_nag_update AJAX nopriv_ function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to delay or disable update notifications.

CVSS:
5.3
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Nov 16, 2023

CVE-2023-47823 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.7

unknown

[en] The FormCraft WordPress plugin before 1.2.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Aug 30, 2023

CVE-2023-3501 on NVD →

FormCraft <= 1.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary w...

CVSS:
4.4
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Aug 2, 2023

CVE-2023-3501 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 3.9.7

unknown

[en] The FormCraft WordPress plugin before 3.9.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

Affected:
up to 3.9.7
Fixed in:
3.9.7
Disclosed:
Jun 27, 2023

CVE-2023-2592 on NVD →

FormCraft Premium <= 3.9.6 - Authenticated(Administrator+) SQL Injection

medium

The FormCraft Premium plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 3.9.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with ad...

CVSS:
6.6
Affected:
up to 3.9.5
Fixed in:
3.9.6
Disclosed:
Jun 5, 2023

CVE-2023-2592 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.10

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in nCrafts FormCraft plugin <= 1.2.6 versions.

Affected:
up to 1.2.10
Fixed in:
1.2.10
Disclosed:
May 15, 2023

CVE-2023-22717 on NVD →

FormCraft <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fcb shortcode

medium

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's fcb shortcode in versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and abo...

CVSS:
6.4
Affected:
up to 1.2.9
Fixed in:
1.2.10
Disclosed:
Apr 19, 2023

CVE-2023-22717 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.6

unknown

[en] The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
Jun 6, 2022

CVE-2022-1647 on NVD →

FormCraft Basic <= 1.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The FormCraft WordPress plugin before 1.2.6 does not sanitise and escape Field Labels, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.5
Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
May 16, 2022

CVE-2022-1647 on NVD →

Formcraft3 <= 3.8.27 - Server Side Request Forgery

critical

The FormCraft WordPress plugin before 3.8.28 does not validate the URL parameter in the formcraft3_get AJAX action, leading to SSRF issues exploitable by unauthenticated users

CVSS:
9.1
Affected:
up to 3.8.28
Fixed in:
3.8.28
Disclosed:
Feb 28, 2022

CVE-2022-0591 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.2

unknown

[en] The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Aug 16, 2019

CVE-2019-15114 on NVD →

FormCraft &#8211; Form Builder [formcraft-form-builder] < 1.2.2

unknown

[en] Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Mar 12, 2019

CVE-2019-5920 on NVD →

FormCraft <= 1.2.1 - Cross-Site Request Forgery

high

The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.

CVSS:
8.8
Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Feb 26, 2019

CVE-2019-15114 on NVD →

FormCraft <= 1.2.1 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.

CVSS:
8.8
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
Feb 26, 2019

CVE-2019-5920 on NVD →

FormCraft Basic 1.0.5 - SQL Injection via id Parameter

critical

The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.

CVSS:
9.8
Affected:
1.0.5 – 1.0.5
Fixed in:
1.0.6
Disclosed:
Jul 5, 2017

CVE-2017-13137 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database