+ 32 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2023-6830
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 6.7.1
|
6.7.1 |
2024-01-08 |
✓ corregido en la última versión
|
|
CVE-2023-2877
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1 |
Autorización incorrecta |
Alta
8,8
|
< 6.3.1
|
6.3.1 |
2023-06-27 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1 |
— |
Desconocido
|
< 6.3.1
|
6.3.1 |
2023-06-01 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1 |
— |
Desconocido
|
< 6.3.1
|
6.3.1 |
2023-05-31 |
✓ corregido en la última versión
|
|
CVE-2023-1405
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.2 |
Deserialización de datos no confiables |
Alta
7,5
|
< 6.2
|
6.2 |
2023-04-06 |
✓ corregido en la última versión
|
|
CVE-2023-0816
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.1 |
Elusión de autenticación mediante suplantación (spoofing) |
Media
6,5
|
< 6.1
|
6.1 |
2023-03-06 |
✓ corregido en la última versión
|
|
CVE-2022-45806
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 |
Falta de control de autorización |
Media
4,3
|
< 5.5.5
|
5.5.5 |
2023-02-03 |
✓ corregido en la última versión
|
|
CVE-2023-24419
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.7 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
7,1
|
< 5.5.7
|
5.5.7 |
2023-02-02 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.7 |
— |
Desconocido
|
< 5.5.7
|
5.5.7 |
2023-02-01 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 |
— |
Desconocido
|
< 5.5.5
|
5.5.5 |
2022-12-21 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 |
— |
Desconocido
|
< 5.5.5
|
5.5.5 |
2022-12-21 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 |
— |
Desconocido
|
< 5.5.5
|
5.5.5 |
2022-12-16 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5 |
— |
Desconocido
|
< 5.5.5
|
5.5.5 |
2022-12-16 |
✓ corregido en la última versión
|
|
CVE-2021-39330
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.0.07 |
— |
Desconocido
|
< 5.0.07
|
5.0.07 |
2021-10-13 |
✓ corregido en la última versión
|
|
CVE-2021-24608
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.0.07 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 5.0.07
|
5.0.07 |
2021-10-06 |
✓ corregido en la última versión
|
|
CVE-2021-24884
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 4.09.05 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Crítica
9,6
|
< 4.09.05
|
4.09.05 |
2021-01-28 |
✓ corregido en la última versión
|
|
CVE-2019-15780
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 4.02.01 |
Deserialización de datos no confiables |
Crítica
9,8
|
< 4.02.01
|
4.02.01 |
2019-08-09 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-20 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-20 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-20 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-13 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-13 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-13 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
2017-11-12 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0.22 |
— |
Desconocido
|
< 2.0.22
|
2.0.22 |
2016-02-16 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.04 |
— |
Desconocido
|
< 1.06.04
|
1.06.04 |
2016-01-29 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.09 |
— |
Desconocido
|
< 1.06.09
|
1.06.09 |
2016-01-29 |
✓ corregido en la última versión
|
|
CVE-2009-4140
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.03 |
— |
Desconocido
|
< 1.06.03
|
1.06.03 |
2009-12-22 |
✓ corregido en la última versión
|
|
CVE-2014-9309
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0 |
— |
Desconocido
|
< 2.0
|
2.0 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2888
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.29 |
— |
Desconocido
|
< 6.29
|
6.29 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2026-2890
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.29 |
— |
Desconocido
|
< 6.29
|
6.29 |
0000-00-00 |
✓ corregido en la última versión
|
|
—
|
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03 |
— |
Desconocido
|
< 2.05.03
|
2.05.03 |
— |
✓ corregido en la última versión
|
CVE-2023-6830
The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered, potentially leading to admin area defacement or redirection to malicious websites. CVE-2024-23522 appears to be a duplicate of this issue.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-2877
Update the WordPress Formidable Forms plugin to the latest available version (at least 6.3.1).
Alex Sanford discovered and reported this Remote Code Execution (RCE) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website. This vulnerability has been fixed in version 6.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1
Update the WordPress Formidable Forms plugin to the latest available version (at least 6.3.1).
WordFence discovered and reported this Broken Access Control vulnerability in WordPress Formidable Forms Plugin. This vulnerability has been fixed in version 6.3.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 6.3.1
The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the screen_page() and can_install_addon_api() functions in versions up to, and including, 6.3. This makes it possible for authenticated attackers, with minimal permissions such as subscribers to retrieve a valid token from the welcome page, and then subsequently install and activate arbitrary plugins onto the site utilizing that key. This can easily be leveraged by attackers to achieve remote code execution as they simply need to install another plugin with a vulnerability or functionality that will aid in further exploitation.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-1405
The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 via deserialization of untrusted input from form submissions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-0816
The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a reliance on various untrusted headers (e.g., 'Client-Ip', 'CF-CONNECTING-IP', etc.) to retrieve the IP address of a client performing a form submission. This makes it possible for unauthenticated users to bypass the plugin's anti-spam protections.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-45806
Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5).
Lana Codes discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 5.5.5.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-24419
Update the WordPress Formidable Forms plugin to the latest available version (at least 5.5.7).
Rafshanzani Suhada discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 5.5.7.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.7
The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.6. This is due to missing or incorrect nonce validation on the 'destroy' function. This makes it possible for unauthenticated attackers to delete form entries via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5
Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5).
An unknown person discovered and reported this Server Side Request Forgery (SSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to cause a website to execute website requests to an arbitrary domain of the attacker. This could allow a malicious actor to find sensitive information. This vulnerability has been fixed in version 5.5.5.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5
Update the WordPress Formidable Form Builder plugin to the latest available version (at least 5.5.5).
Wordfence discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress Formidable Forms Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. For example a password change which will then allow the malicious actor to login into the admin account. This vulnerability has been fixed in version 5.5.5.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5
The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on two functions handling migrations and data loading. This makes it possible for unauthenticated attackers to invoke those functions, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.5.5
The Formidable Form Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 5.5.4 due to insufficient URL restrictions on the 'plugin' parameter passed to the the install_addon function. This makes it possible for authenticated users, with administrative privileges, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2021-39330
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Thinkland Security Team in WordPress Formidable Forms plugin (versions <= 5.0.06).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2021-24608
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2021-24884
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attacker to perform arbitrary actions on an affected system with the privileges of the user. These actions include stealing the users account by changing their password or allowing attackers to submit their own code through an authenticated user resulting in Remote Code Execution. If an authenticated user who is able to edit Wordpress PHP Code in any kind, clicks the malicious link, PHP code can be edited.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2019-15780
The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress WordPress plugin was affected by an Unsafe Deserialisation security vulnerability.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
Blind SQL Injection (SQLi) vulnerability found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). This vulnerability allows an attacker to enumerate databases and tables and retrieve their contents.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
Multiple Cross-Site Scripting (XSS) vulnerabilities found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). Reflected Cross-Site Scripting vulnerability in form preview and Stored Cross-Site Scripting vulnerability in form entries.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
Multiple vulnerabilities found by Jouko Pynnönen in WordPress Formidable Forms plugin (versions <=2.05.02). Unauthenticated preview function allowing shortcodes, unauthenticated form entries retrieval and Server-Side Code Execution via iThemes Sync.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
The Formidable Form Builder plugin for WordPress is vulnerable to SQL Injection via the ‘display-frm-data’ shortcode in versions before 2.05.03 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
The Formidable Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'before_html' parameter passed through the frm_forms_preview AJAX action in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser whenever they successfully trick a victim into performing an action like clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.0.22
The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.21. This is due to missing nonce and capability checks on the 'frm_fill_licenses' and 'frm_ajax' AJAX actions. This makes it possible for unauthenticated attackers to access leaked nonces and modify form fields.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.04
This plugin is prone to remote code execution because of ofc_upload_image.php file parameters ($_GET[ 'name' ] and $HTTP_RAW_POST_DATA).
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 1.06.09
This plugin is prone to unspecified issues.
Update the plugin.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2009-4140
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2014-9309
The Formidable Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby’ parameter in versions up to, and including, 1.07.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2888
The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-controlled JSON input and then using those values to recalculate payment amounts via field shortcode resolution in `generate_false_entry()`. The handler relies on a nonce that is publicly exposed in the page's JavaScript (`frm_stripe_vars.nonce`), which provides CSRF protection but not authorization. This makes it possible for unauthenticated attackers to manipulate PaymentIntent amounts before payment completion on forms using dynamic pricing with field shortcodes, effectively paying a reduced amount for goods or services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2026-2890
The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Stripe PaymentIntent status without comparing the intent's charged amount against the expected payment amount, and the `verify_intent()` function validating only client secret ownership without binding intents to specific forms or actions. This makes it possible for unauthenticated attackers to reuse a PaymentIntent from a completed low-value payment to mark a high-value payment as complete, effectively bypassing payment for goods or services.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 2.05.03
The plugin was affected by Multiple Vulnerabilities:
- Unauthenticated preview function allowing shortcodes
- SQL injection
- Unauthenticated form entries retrieval
- Reflected XSS in form preview
- Stored XSS in form entries
- Server-side code execution via iThemes Sync
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Mantén Formidable actualizado — 6.33.1 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.