Formidable Registration <= 2.11 - Authenticated (Contributor+) Arbitrary User Password Reset To Account Takeover
highThe WordPress User Registration Forms by Formidable Forms plugin for WordPress is vulnerable to arbitrary user password reset and account takeover in all versions up to, and including, 2.11. This is due to the plugin allowing users with access to the editor to utilize the frm-set-password-link shortcode and supply any...
- CVSS:
- 8.8
- Affected:
- up to 2.11
- Fixed in:
- 2.12
- Disclosed:
- Feb 19, 2024