Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
Minimum safe version
6.29
Update to 6.29 or later to address 40 fixable vulnerabilities
Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter
CVE-2024-11188
CVE-2024-9768
CVE-2017-20194
CVE-2017-20192
CVE-2024-6725
CVE-2024-23522
CVE-2024-0660
CVE-2023-6830
CVE-2023-6842
CVE-2023-2877
WordPress Formidable Forms Plugin < 6.3.1 is vulnerable to Broken Access Control
Formidable Forms <= 6.3 - Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation
CVE-2009-4140
Formidable Forms < 2.05.03 - Multiple Vulnerabilities
CVE-2023-1405
CVE-2023-0816
CVE-2022-45806
CVE-2023-24419
Formidable Form Builder <= 5.5.6 - Cross-Site Request Forgery
Formidable Form Builder <= 2.0.21 - Missing Authorization Checks
Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure
Formidable Form Builder < 2.05.03 - Reflected Cross-Site Scripting
Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting
Formidable Form Builder < 2.05.03 - SQL Injection
WordPress Formidable Forms Plugin <= 5.5.4 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Formidable Forms Plugin <= 5.5.4 is vulnerable to Server Side Request Forgery (SSRF)
Formidable Forms <= 5.5.4 - Authenticated (Admin+) Server-Side Request Forgery
Formidable Form Builder <= 5.5.4 - Cross-Site Request Forgery
WordPress Formidable Forms Plugin <= 1.07.11 - Blind SQL Injection
WordPress Formidable Forms Plugin <= 1.06.08 - Unspecified Vulnerabilities
WordPress Formidable Forms Plugin <= 1.06.03 - Remote Code Execution
WordPress Formidable Forms plugin <=2.05.02 - Multiple vulnerabilities
WordPress Formidable Forms plugin <=2.05.02 - Multiple Cross-Site Scripting (XSS) vulnerabilities
WordPress Formidable Forms plugin <=2.05.02 - SQL Injection (SQLi) vulnerability
CVE-2021-39330
CVE-2019-15780
CVE-2021-24884
CVE-2021-24608