HTML Injection Vulnerability in Formidable Forms Plugin for WordPress
CVE-2023-6830
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 January 2024
What is CVE-2023-6830?
The Formidable Forms plugin for WordPress is susceptible to HTML injection, allowing unauthenticated users to inject arbitrary HTML into form fields. Administrators viewing submitted form data may encounter this injected code in the Entries View Page, which could lead to potential admin area defacement or redirection to harmful sites. It is crucial for users to update to the latest version to mitigate these risks and protect their web applications from unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Formidable Forms β Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder * <= 6.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved