HTML Injection Vulnerability in Formidable Forms Plugin for WordPress
CVE-2023-6830

6.1MEDIUM

Summary

The Formidable Forms plugin for WordPress is susceptible to HTML injection, allowing unauthenticated users to inject arbitrary HTML into form fields. Administrators viewing submitted form data may encounter this injected code in the Entries View Page, which could lead to potential admin area defacement or redirection to harmful sites. It is crucial for users to update to the latest version to mitigate these risks and protect their web applications from unauthorized access.

Affected Version(s)

Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder * <= 6.7

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro Paniago
.