plugin

Formidable Vulnerabilities

64 known security issues reported for the Formidable WordPress plugin. Most recent disclosed Aug 25, 2026.

4 critical 6 high 16 medium

Running Formidable on your site? Check whether your installed version is affected.

Scan your site free

Formidable Forms <= 6.33.1 - Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter

high

The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization and output escaping. This makes it possible f...

CVSS:
7.2
Affected:
up to 6.33.1
Fixed in:
6.34
Disclosed:
Aug 25, 2026

CVE-2026-18331 on NVD →

Formidable Forms <= 6.32.0 - Unauthenticated Payment Bypass

medium

The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including, 6.32.0. This makes it possible for unauthenticated attackers to bypass payments.

CVSS:
5.3
Affected:
up to 6.32.0
Fixed in:
6.32.1
Disclosed:
Jun 25, 2026

CVE-2026-11361 on NVD →

Formidable Forms - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter vulnerability

medium

Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter vulnerability

CVSS:
5.3
Affected:
up to 6.28
Fixed in:
6.29
Disclosed:
Mar 13, 2026

Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter

medium

The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-controlled JSON input and then using thos...

CVSS:
5.3
Affected:
up to 6.28
Fixed in:
6.29
Disclosed:
Mar 12, 2026

CVE-2026-2888 on NVD →

Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse

high

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without comparing...

CVSS:
7.5
Affected:
up to 6.28
Fixed in:
6.29
Disclosed:
Mar 12, 2026

CVE-2026-2890 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.5

unknown

[en] Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Dec 13, 2024

CVE-2022-45806 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.16.2

unknown

[en] The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and outp...

Affected:
up to 6.16.2
Fixed in:
6.16.2
Disclosed:
Nov 23, 2024

CVE-2024-11188 on NVD →

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter

medium

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output es...

CVSS:
6.1
Affected:
up to 6.16.1.2
Fixed in:
6.16.2
Disclosed:
Nov 22, 2024

CVE-2024-11188 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.14.1

unknown

[en] The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 6.14.1
Fixed in:
6.14.1
Disclosed:
Nov 21, 2024

CVE-2024-9768 on NVD →

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.14 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
4.4
Affected:
up to 6.14
Fixed in:
6.14.1
Disclosed:
Oct 31, 2024

CVE-2024-9768 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

[en] The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Oct 16, 2024

CVE-2017-20194 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

[en] The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Oct 16, 2024

CVE-2017-20192 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.11.2

unknown

[en] The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it...

Affected:
up to 6.11.2
Fixed in:
6.11.2
Disclosed:
Jul 31, 2024

CVE-2024-6725 on NVD →

Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possi...

CVSS:
4.9
Affected:
up to 6.11.1
Fixed in:
6.11.2
Disclosed:
Jul 30, 2024

CVE-2024-6725 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.7.1

unknown

[en] Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through 6.7.

Affected:
up to 6.7.1
Fixed in:
6.7.1
Disclosed:
May 17, 2024

CVE-2024-23522 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.8

unknown

[en] The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possibl...

Affected:
up to 6.8
Fixed in:
6.8
Disclosed:
Feb 5, 2024

CVE-2024-0660 on NVD →

Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible for...

CVSS:
6.1
Affected:
up to 6.7.2
Fixed in:
6.8
Disclosed:
Jan 26, 2024

CVE-2024-0660 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.2

unknown

[en] The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

Affected:
up to 6.2
Fixed in:
6.2
Disclosed:
Jan 16, 2024

CVE-2023-1405 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.7.1

unknown

[en] The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rende...

Affected:
up to 6.7.1
Fixed in:
6.7.1
Disclosed:
Jan 9, 2024

CVE-2023-6830 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.7.1

unknown

[en] The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input sanitization and output...

Affected:
up to 6.7.1
Fixed in:
6.7.1
Disclosed:
Jan 9, 2024

CVE-2023-6842 on NVD →

Formidable Forms <= 6.7 - HTML Injection

medium

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered,...

CVSS:
6.5
Affected:
up to 6.7
Fixed in:
6.7.1
Disclosed:
Jan 8, 2024

CVE-2023-6830 on NVD →

Formidable Forms <= 6.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input sanitization and output escap...

CVSS:
4.4
Affected:
up to 6.7
Fixed in:
6.7.1
Disclosed:
Jan 8, 2024

CVE-2023-6842 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.3.1

unknown

[en] The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin reposit...

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Jun 27, 2023

CVE-2023-2877 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.3.1

unknown

Update the WordPress Formidable Forms plugin to the latest available version (at least 6.3.1). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Formidable Forms Plugin. This vulnerability has been fixed in version 6.3.1.

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
Jun 1, 2023

Formidable Forms <= 6.3 - Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation

medium

The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the screen_page() and can_install_addon_api() functions in versions up to, and including, 6.3. This makes it possible for authenticated attackers, with minimal permis...

CVSS:
6.5
Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
May 31, 2023

CVE-2023-2877 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.3.1

unknown

The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the screen_page() and can_install_addon_api() functions in versions up to, and including, 6.3. This makes it possible for authenticated attackers, with minimal permis...

Affected:
up to 6.3.1
Fixed in:
6.3.1
Disclosed:
May 31, 2023

Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection

critical

The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 via deserialization of untrusted input from form submissions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present...

CVSS:
9.8
Affected:
up to 6.1.2
Fixed in:
6.2
Disclosed:
Apr 6, 2023

CVE-2023-1405 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 6.1

unknown

[en] The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

Affected:
up to 6.1
Fixed in:
6.1
Disclosed:
Mar 27, 2023

CVE-2023-0816 on NVD →

Formidable Forms <= 6.0.1 - IP Spoofing via HTTP header

medium

The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a reliance on various untrusted headers (e.g., 'Client-Ip', 'CF-CONNECTING-IP', etc.) to retrieve the IP address of a client performing a form submission. This makes it possible for unauthenticated use...

CVSS:
5.3
Affected:
up to 6.0.1
Fixed in:
6.1
Disclosed:
Mar 6, 2023

CVE-2023-0816 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions.

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
Feb 28, 2023

CVE-2023-24419 on NVD →

Formidable Form Builder <= 5.5.6 - Cross-Site Request Forgery

high

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.6. This is due to missing or incorrect nonce validation on the 'destroy' function. This makes it possible for unauthenticated attackers to delete form entries via forged request granted the...

CVSS:
7.1
Affected:
up to 5.5.6
Fixed in:
5.5.7
Disclosed:
Feb 1, 2023

CVE-2023-24419 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.7

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.6. This is due to missing or incorrect nonce validation on the 'destroy' function. This makes it possible for unauthenticated attackers to delete form entries via forged request granted the...

Affected:
up to 5.5.7
Fixed in:
5.5.7
Disclosed:
Feb 1, 2023

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.5

unknown

Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5). An unknown person discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to cause a website to execute website requests to...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Dec 21, 2022

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.5

unknown

Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5). Wordfence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actio...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Dec 21, 2022

Formidable Form Builder <= 5.5.4 - Cross-Site Request Forgery

medium

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on two functions handling migrations and data loading. This makes it possible for unauthenticated attackers to invoke those functions...

CVSS:
5.4
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
Dec 16, 2022

CVE-2022-45806 on NVD →

Formidable Forms <= 5.5.4 - Authenticated (Admin+) Server-Side Request Forgery

medium

The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.5.4 due to insufficient URL restrictions on the 'plugin' parameter passed to the the install_addon function. This makes it possible for authenticated users, with administrative privileges, t...

CVSS:
4.7
Affected:
up to 5.5.4
Fixed in:
5.5.5
Disclosed:
Dec 16, 2022

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.5

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on two functions handling migrations and data loading. This makes it possible for unauthenticated attackers to invoke those functions...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Dec 16, 2022

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.5.5

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.5.4 due to insufficient URL restrictions on the 'plugin' parameter passed to the the install_addon function. This makes it possible for authenticated users, with administrative privileges, t...

Affected:
up to 5.5.5
Fixed in:
5.5.5
Disclosed:
Dec 16, 2022

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.0.07

unknown

[en] The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 5.0.07
Fixed in:
5.0.07
Disclosed:
Oct 25, 2021

CVE-2021-24608 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 4.09.05

unknown

[en] The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link...

Affected:
up to 4.09.05
Fixed in:
4.09.05
Disclosed:
Oct 25, 2021

CVE-2021-24884 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 5.0.07

unknown
Affected:
up to 5.0.07
Fixed in:
5.0.07
Disclosed:
Oct 14, 2021

CVE-2021-39330 on NVD →

Formidable Form Builder <= 5.0.06 - Admin+ Stored Cross-Site Scripting

medium

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 5.0.07
Fixed in:
5.0.07
Disclosed:
Oct 6, 2021

CVE-2021-24608 on NVD →

Formidable Form Builder <= 4.09.04 - Unauthenticated Stored Cross-Site Scripting

critical

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If...

CVSS:
9.6
Affected:
up to 4.09.05
Fixed in:
4.09.05
Disclosed:
Jan 28, 2021

CVE-2021-24884 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 4.02.01

unknown

[en] The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

Affected:
up to 4.02.01
Fixed in:
4.02.01
Disclosed:
Aug 29, 2019

CVE-2019-15780 on NVD →

Formidable Form Builder <= 4.02 - PHP Object Injection

critical

The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.

CVSS:
9.8
Affected:
up to 4.02.01
Fixed in:
4.02.01
Disclosed:
Aug 9, 2019

CVE-2019-15780 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

Blind SQL Injection (SQLi) vulnerability found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). This vulnerability allows an attacker to enumerate databases and tables and retrieve their contents.

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 20, 2017

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

Multiple Cross-Site Scripting (XSS) vulnerabilities found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). Reflected Cross-Site Scripting vulnerability in form preview and Stored Cross-Site Scripting vulnerability in form entries.

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 20, 2017

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

Multiple vulnerabilities found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). Unauthenticated preview function allowing shortcodes, unauthenticated form entries retrieval and Server-Side Code Execution via iThemes Sync.

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 20, 2017

Formidable Form Builder < 2.05.03 - SQL Injection

high

The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode in versions before 2.05.03 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additio...

CVSS:
8.6
Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 13, 2017

Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting

high

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...

CVSS:
8.3
Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 13, 2017

CVE-2017-20192 on NVD →

Formidable Form Builder < 2.05.03 - Reflected Cross-Site Scripting

medium

The Formidable Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'before_html' parameter passed through the frm_forms_preview AJAX action in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrar...

CVSS:
6.1
Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 13, 2017

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'before_html' parameter passed through the frm_forms_preview AJAX action in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrar...

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 13, 2017

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 13, 2017

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode in versions before 2.05.03 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additio...

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 13, 2017

Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure

medium

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

CVSS:
5.3
Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 12, 2017

CVE-2017-20194 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Affected:
up to 2.05.03
Fixed in:
2.05.03
Disclosed:
Nov 12, 2017

Formidable Form Builder <= 2.0.21 - Missing Authorization Checks

critical

The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.21. This is due to missing nonce and capability checks on the 'frm_fill_licenses' and 'frm_ajax' AJAX actions. This makes it possible for unauthenticated attackers to access leaked nonces and mod...

CVSS:
9.1
Affected:
up to 2.0.21
Fixed in:
2.0.22
Disclosed:
Feb 16, 2016

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.0.22

unknown

The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.21. This is due to missing nonce and capability checks on the 'frm_fill_licenses' and 'frm_ajax' AJAX actions. This makes it possible for unauthenticated attackers to access leaked nonces and mod...

Affected:
up to 2.0.22
Fixed in:
2.0.22
Disclosed:
Feb 16, 2016

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 1.06.09

unknown

This plugin is prone to unspecified issues. Update the plugin.

Affected:
up to 1.06.09
Fixed in:
1.06.09
Disclosed:
Jan 29, 2016

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 1.06.04

unknown

This plugin is prone to remote code execution because of ofc_upload_image.php file parameters ($_GET[ 'name' ] and $HTTP_RAW_POST_DATA). Update the plugin.

Affected:
up to 1.06.04
Fixed in:
1.06.04
Disclosed:
Jan 29, 2016

Formidable Form Builder <= 1.07.11 - SQL Injection

high

The Formidable Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.07.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated...

CVSS:
8.8
Affected:
up to 1.07.11
Fixed in:
2.0
Disclosed:
Jan 26, 2016

CVE-2014-9309 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 1.06.03

unknown

[en] Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitr...

Affected:
up to 1.06.03
Fixed in:
1.06.03
Disclosed:
Dec 22, 2009

CVE-2009-4140 on NVD →

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.05.03

unknown

The plugin was affected by Multiple Vulnerabilities: - Unauthenticated preview function allowing shortcodes - SQL injection - Unauthenticated form entries retrieval - Reflected XSS in form preview - Stored XSS in form entries - Server-side code execution via iThemes Sync

Affected:
up to 2.05.03
Fixed in:
2.05.03

Formidable Forms &#8211; Contact Form Plugin, Survey, Quiz, Payment, Calculator Form &amp; Custom Form Builder [formidable] < 2.0

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.0
Fixed in:
2.0

CVE-2014-9309 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database