Medium 6.4
2025-02-18< 3.0.0
CVE-2024-13501
Minimum safe version
3.0.0
Update to 3.0.0 or later to address 6 fixable vulnerabilities
CVE-2024-13501
CVE-2023-49768
WP-FormAssembly <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP-FormAssembly <= 2.0.8 - Limited Server Side Request Forgery via 'formassembly' shortcode
WordPress WP-FormAssembly Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-45852