Formidable Forms Signature Online Contract Automation <= 2.0.1 - Unauthenticated Insecure Direct Object Reference
mediumThe Formidable Forms Signature Online Contract Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.1 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Jul 28, 2026