WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Formidable?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Formidable — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: formidable
  • 300000+ instalaciones activas

contact formcustom formform builderformspayment form

Estado de mantenimiento

  • Última versión conocida: 6.33.1
  • Requiere PHP: 7.0+

Vulnerabilidades conocidas

22 CVEs conocidos registrados para Formidable.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-11188 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.16.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 6.16.2 6.16.2 2024-11-22 ✓ corregido en la última versión
CVE-2024-9768 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.14.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 6.14.1 6.14.1 2024-10-31 ✓ corregido en la última versión
CVE-2017-20192 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 8,3 < 2.05.03 2.05.03 2024-10-16 ✓ corregido en la última versión
CVE-2017-20194 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Exposición de información sensible a un actor no autorizado Media 5,3 < 2.05.03 2.05.03 2024-10-16 ✓ corregido en la última versión
CVE-2024-6725 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.11.2 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 6.11.2 6.11.2 2024-07-30 ✓ corregido en la última versión
CVE-2024-23522 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.7.1 Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) Media 5,3 < 6.7.1 6.7.1 2024-05-17 ✓ corregido en la última versión
CVE-2024-0660 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.8 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 6.8 6.8 2024-01-26 ✓ corregido en la última versión
CVE-2023-6842 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.7.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 6.7.1 6.7.1 2024-01-08 ✓ corregido en la última versión

CVE-2024-11188

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-9768

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2017-20192

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2017-20194

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-6725

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-23522

Update the WordPress Formidable Forms plugin to the latest available version (at least 6.7.1). Revan Arifio discovered and reported this Content Injection vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to inject their own content into pages and posts of your website. This could also be abused to inject phishing pages into your website. This vulnerability has been fixed in version 6.7.1. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-0660

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_settings function. This makes it possible for unauthenticated attackers to change form settings and add malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-6842

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. By default, this only affects multi-site installations and installations where unfiltered_html has been disabled. However, in the formidable settings admins can extend form creation, deletion and other management permissions to other user types, which makes it possible for this vulnerability to be exploited by lower level user types as long as they have been granted the proper permissions.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 32 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2023-6830 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.7.1 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 6.7.1 6.7.1 2024-01-08 ✓ corregido en la última versión
CVE-2023-2877 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1 Autorización incorrecta Alta 8,8 < 6.3.1 6.3.1 2023-06-27 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1 Desconocido < 6.3.1 6.3.1 2023-06-01 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1 Desconocido < 6.3.1 6.3.1 2023-05-31 ✓ corregido en la última versión
CVE-2023-1405 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.2 Deserialización de datos no confiables Alta 7,5 < 6.2 6.2 2023-04-06 ✓ corregido en la última versión
CVE-2023-0816 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.1 Elusión de autenticación mediante suplantación (spoofing) Media 6,5 < 6.1 6.1 2023-03-06 ✓ corregido en la última versión
CVE-2022-45806 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 Falta de control de autorización Media 4,3 < 5.5.5 5.5.5 2023-02-03 ✓ corregido en la última versión
CVE-2023-24419 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.7 Falsificación de petición en sitios cruzados (CSRF) Alta 7,1 < 5.5.7 5.5.7 2023-02-02 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.7 Desconocido < 5.5.7 5.5.7 2023-02-01 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 Desconocido < 5.5.5 5.5.5 2022-12-21 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 Desconocido < 5.5.5 5.5.5 2022-12-21 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 Desconocido < 5.5.5 5.5.5 2022-12-16 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 Desconocido < 5.5.5 5.5.5 2022-12-16 ✓ corregido en la última versión
CVE-2021-39330 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.0.07 Desconocido < 5.0.07 5.0.07 2021-10-13 ✓ corregido en la última versión
CVE-2021-24608 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.0.07 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 5.0.07 5.0.07 2021-10-06 ✓ corregido en la última versión
CVE-2021-24884 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 4.09.05 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Crítica 9,6 < 4.09.05 4.09.05 2021-01-28 ✓ corregido en la última versión
CVE-2019-15780 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 4.02.01 Deserialización de datos no confiables Crítica 9,8 < 4.02.01 4.02.01 2019-08-09 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-20 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-20 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-20 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-13 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-13 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-13 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 2017-11-12 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0.22 Desconocido < 2.0.22 2.0.22 2016-02-16 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.04 Desconocido < 1.06.04 1.06.04 2016-01-29 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.09 Desconocido < 1.06.09 1.06.09 2016-01-29 ✓ corregido en la última versión
CVE-2009-4140 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.03 Desconocido < 1.06.03 1.06.03 2009-12-22 ✓ corregido en la última versión
CVE-2014-9309 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0 Desconocido < 2.0 2.0 0000-00-00 ✓ corregido en la última versión
CVE-2026-2888 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.29 Desconocido < 6.29 6.29 0000-00-00 ✓ corregido en la última versión
CVE-2026-2890 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.29 Desconocido < 6.29 6.29 0000-00-00 ✓ corregido en la última versión
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 Desconocido < 2.05.03 2.05.03 ✓ corregido en la última versión

CVE-2023-6830

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered, potentially leading to admin area defacement or redirection to malicious websites. CVE-2024-23522 appears to be a duplicate of this issue.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-2877

Update the WordPress Formidable Forms plugin to the latest available version (at least 6.3.1). Alex Sanford discovered and reported this Remote Code Execution (RCE) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website. This vulnerability has been fixed in version 6.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1

Update the WordPress Formidable Forms plugin to the latest available version (at least 6.3.1). WordFence discovered and reported this Broken Access Control vulnerability in WordPress Formidable Forms Plugin. This vulnerability has been fixed in version 6.3.1.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1

The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the screen_page() and can_install_addon_api() functions in versions up to, and including, 6.3. This makes it possible for authenticated attackers, with minimal permissions such as subscribers to retrieve a valid token from the welcome page, and then subsequently install and activate arbitrary plugins onto the site utilizing that key. This can easily be leveraged by attackers to achieve remote code execution as they simply need to install another plugin with a vulnerability or functionality that will aid in further exploitation.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-1405

The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 via deserialization of untrusted input from form submissions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-0816

The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a reliance on various untrusted headers (e.g., 'Client-Ip', 'CF-CONNECTING-IP', etc.) to retrieve the IP address of a client performing a form submission. This makes it possible for unauthenticated users to bypass the plugin's anti-spam protections.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-45806

Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5). Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 5.5.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-24419

Update the WordPress Formidable Forms plugin to the latest available version (at least 5.5.7). Rafshanzani Suhada discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 5.5.7.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.7

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.6. This is due to missing or incorrect nonce validation on the 'destroy' function. This makes it possible for unauthenticated attackers to delete form entries via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5

Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5). An unknown person discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information. This vulnerability has been fixed in version 5.5.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5

Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5). Wordfence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 5.5.5.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on two functions handling migrations and data loading. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5

The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.5.4 due to insufficient URL restrictions on the 'plugin' parameter passed to the the install_addon function. This makes it possible for authenticated users, with administrative privileges, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2021-39330

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Thinkland Security Team in WordPress Formidable Forms plugin (versions <= 5.0.06).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24608

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2021-24884

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edited.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2019-15780

The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress WordPress plugin was affected by an Unsafe Deserialisation security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

Blind SQL Injection (SQLi) vulnerability found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). This vulnerability allows an attacker to enumerate databases and tables and retrieve their contents.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

Multiple Cross-Site Scripting (XSS) vulnerabilities found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). Reflected Cross-Site Scripting vulnerability in form preview and Stored Cross-Site Scripting vulnerability in form entries.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

Multiple vulnerabilities found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). Unauthenticated preview function allowing shortcodes, unauthenticated form entries retrieval and Server-Side Code Execution via iThemes Sync.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode in versions before 2.05.03 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

The Formidable Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'before_html' parameter passed through the frm_forms_preview AJAX action in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser whenever they successfully trick a victim into performing an action like clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0.22

The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.21. This is due to missing nonce and capability checks on the 'frm_fill_licenses' and 'frm_ajax' AJAX actions. This makes it possible for unauthenticated attackers to access leaked nonces and modify form fields.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.04

This plugin is prone to remote code execution because of ofc_upload_image.php file parameters ($_GET[ 'name' ] and $HTTP_RAW_POST_DATA). Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.09

This plugin is prone to unspecified issues. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2009-4140

Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2014-9309

The Formidable Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.07.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2888

The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-controlled JSON input and then using those values to recalculate payment amounts via field shortcode resolution in `generate_false_entry()`. The handler relies on a nonce that is publicly exposed in the page's JavaScript (`frm_stripe_vars.nonce`), which provides CSRF protection but not authorization. This makes it possible for unauthenticated attackers to manipulate PaymentIntent amounts before payment completion on forms using dynamic pricing with field shortcodes, effectively paying a reduced amount for goods or services.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-2890

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without comparing the intent's charged amount against the expected payment amount, and the `verify_intent()` function validating only client secret ownership without binding intents to specific forms or actions. This makes it possible for unauthenticated attackers to reuse a PaymentIntent from a completed low-value payment to mark a high-value payment as complete, effectively bypassing payment for goods or services.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03

The plugin was affected by Multiple Vulnerabilities: - Unauthenticated preview function allowing shortcodes - SQL injection - Unauthenticated form entries retrieval - Reflected XSS in form preview - Stored XSS in form entries - Server-side code execution via iThemes Sync

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Formidable actualizado — 6.33.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.