HTML Injection Vulnerability in Formidable Forms Plugin for WordPress
CVE-2023-6830
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 January 2024
What is CVE-2023-6830?
The Formidable Forms plugin for WordPress is susceptible to HTML injection, allowing unauthenticated users to inject arbitrary HTML into form fields. Administrators viewing submitted form data may encounter this injected code in the Entries View Page, which could lead to potential admin area defacement or redirection to harmful sites. It is crucial for users to update to the latest version to mitigate these risks and protect their web applications from unauthorized access.
Affected Version(s)
Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder * <= 6.7