Extension WordPress
Vulnérabilités Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More
Cette page rassemble les failles publiées pour Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More
23 fiches
Formidable Forms <= 6.28 – Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter
The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with…
*-6.28
6.29
12/03/2026
Formidable Forms <= 6.28 – Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse
The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely…
*-6.28
6.29
12/03/2026
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 – Reflected Cross-Site Scripting via Custom HTML Form Parameter
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and…
*-6.16.1.2
6.16.2
22/11/2024
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.14 – Authenticated (Admin+) Stored Cross-Site Scripting
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to…
*-6.14
6.14.1
31/10/2024
Formidable Forms <= 6.11.1 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due…
*-6.11.1
6.11.2
30/07/2024
Formidable Forms <= 6.7.2 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or…
*-6.7.2
6.8
26/01/2024
Formidable Forms <= 6.7 – HTML Injection
The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by…
*-6.7
6.7.1
08/01/2024
Formidable Forms <= 6.7 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up…
*-6.7
6.7.1
08/01/2024
Formidable Forms <= 6.3 – Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation
The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the screen_page() and can_install_addon_api() functions in versions up to, and including, 6.3. This makes it possible…
[*, 6.3.1)
6.3.1
31/05/2023
Formidable Forms <= 6.1.2 – Unauthenticated PHP Object Injection
The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 via deserialization of untrusted input from form submissions. This allows unauthenticated attackers to inject a PHP Object. No POP…
*-6.1.2
6.2
06/04/2023
Formidable Forms <= 6.0.1 – IP Spoofing via HTTP header
The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a reliance on various untrusted headers (e.g., 'Client-Ip', 'CF-CONNECTING-IP', etc.) to retrieve the IP address of a client…
*-6.0.1
6.1
06/03/2023
Formidable Form Builder <= 5.5.6 – Cross-Site Request Forgery
The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.6. This is due to missing or incorrect nonce validation on the 'destroy' function. This makes it possible for…
*-5.5.6
5.5.7
01/02/2023
Formidable Forms <= 5.5.4 – Authenticated (Admin+) Server-Side Request Forgery
The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.5.4 due to insufficient URL restrictions on the 'plugin' parameter passed to the the install_addon function. This makes it…
*-5.5.4
5.5.5
16/12/2022
Formidable Form Builder <= 5.5.4 – Cross-Site Request Forgery
The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on two functions handling migrations and data loading. This…
*-5.5.4
5.5.5
16/12/2022
Formidable Form Builder <= 5.0.06 – Admin+ Stored Cross-Site Scripting
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html…
[*, 5.0.07)
5.0.07
06/10/2021
Formidable Form Builder <= 4.09.04 – Unauthenticated Stored Cross-Site Scripting
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to…
[*, 4.09.05)
4.09.05
28/01/2021
Formidable Form Builder <= 4.02 – PHP Object Injection
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
[*, 4.02.01)
4.02.01
09/08/2019
Formidable Form Builder < 2.05.03 – Unauthenticated Stored Cross-Site Scripting
The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible…
[*, 2.05.03)
2.05.03
13/11/2017
Formidable Form Builder < 2.05.03 – Reflected Cross-Site Scripting
The Formidable Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'before_html' parameter passed through the frm_forms_preview AJAX action in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it…
[*, 2.05.03)
2.05.03
13/11/2017
Formidable Form Builder < 2.05.03 – SQL Injection
The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode in versions before 2.05.03 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
[*, 2.05.03)
2.05.03
13/11/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.