Extension WordPress
Vulnérabilités Forminator Forms – Contact Form, Payment Form & Custom Form Builder, page 3
Cette page rassemble les failles publiées pour Forminator Forms – Contact Form, Payment Form & Custom Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Forminator Forms – Contact Form, Payment Form & Custom Form Builder
57 fiches
Forminator <= 1.29.2 – Authenticated (Admin+) SQL Injection
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.29.2 due to insufficient escaping on the user…
*-1.29.2
1.29.3
18/04/2024
Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.29.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ forminator_form shortcode attribute in versions up to, and including, 1.29.2 due to insufficient input sanitization…
*-1.29.2
1.29.3
08/04/2024
Forminator <= 1.29.0 – Unauthenticated Stored Cross-Site Scripting via File Upload
The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.29.0
1.29.1
29/03/2024
Forminator <= 1.29.0 – Reflected Cross-Site Scripting
The Forminator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-1.29.0
1.29.1
25/03/2024
Forminator <= 1.27.0 – Authenticated (Administrator+) Arbitrary File Upload
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above…
*-1.27.0
1.28.0
14/11/2023
Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.27.0 – Authenticated (Admin+) Stored Cross-Site Scripting
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'redirect-url' field located in the form submission settings in all versions up to, and including, 1.26.0…
*-1.26.0
1.27.0
27/10/2023
Forminator <= 1.24.6 – Unauthenticated Arbitrary File Upload
The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This…
*-1.24.6
1.25.0
29/08/2023
Forminator <= 1.24.1 – Reflected Cross-Site Scripting
The Forminator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.24.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
*-1.24.1
1.24.4
10/07/2023
Forminator <= 1.23.3 – Race Condition to Multiple Poll Voting
The Forminator plugin for WordPress is vulnerable to a race condition in versions up to, and including, 1.23.3. This is due to improper validation on the poll voting functionality. This makes it possible for unauthenticated attackers to make…
*-1.23.3
1.24.1
12/06/2023
Forminator <= 1.22.1 – Missing Authorization on 'hubspot_support_request' AJAX function
The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'hubspot_support_request' AJAX function in versions up to, and including, 1.22.1. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-1.22.1
1.23.3
12/04/2023
Forminator <= 1.22.1 – Missing Authorization on 'load_recaptcha_preview' AJAX function
The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'load_recaptcha_preview' AJAX function in versions up to, and including, 1.22.1. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-1.22.1
1.23.3
12/04/2023
Forminator <= 1.22.1 – Missing Authorization on 'load_hcaptcha_preview' AJAX function
The Forminator plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'load_hcaptcha_preview' AJAX function in versions up to, and including, 1.22.1. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-1.22.1
1.23.3
12/04/2023
Forminator <= 1.15.2 – Admin+ Stored Cross-Site Scripting
The Forminator WordPress plugin before 1.15.4 does not sanitize and escape the email field label, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
[*, 1.15.4)
1.15.4
20/10/2021
Forminator <= 1.14.11 – Unauthenticated Stored Cross-Site Scripting
The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.14.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
[*, 1.14.12)
1.14.12
14/07/2021
Forminator – Contact Form, Payment Form & Custom Form Builder <= 1.13.4 – Cross-Site Request Forgery Bypass
The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.13.4. This is due to missing or incorrect nonce validation on the…
[*, 1.13.5)
1.13.5
01/03/2021
Forminator Plugin <= 1.5.3.1 – SQL Injection
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/admin.php?page=forminator-entries entry[] parameter if the attacker has the delete permission.
[*, 1.6)
1.6
06/02/2019
Forminator Plugin <= 1.5.4 – Cross-Site Scripting
The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has XSS via a custom input field of a poll.
[*, 1.6)
1.6
06/02/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.