plugin

Formidable Registration Vulnerabilities

1 known security issue reported for the Formidable Registration WordPress plugin. Most recent disclosed Feb 19, 2024.

1 high

Running Formidable Registration on your site? Check whether your installed version is affected.

Scan your site free

Formidable Registration <= 2.11 - Authenticated (Contributor+) Arbitrary User Password Reset To Account Takeover

high

The WordPress User Registration Forms by Formidable Forms plugin for WordPress is vulnerable to arbitrary user password reset and account takeover in all versions up to, and including, 2.11. This is due to the plugin allowing users with access to the editor to utilize the frm-set-password-link shortcode and supply any...

CVSS:
8.8
Affected:
up to 2.11
Fixed in:
2.12
Disclosed:
Feb 19, 2024

CVE-2024-1290 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database