CVE · Medium

CVE-2021-24608 — Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.0.07

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24608 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 5.0.07 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 5.0.07 5.0.07 2021-10-06

CVE-2021-24608

The Formidable Forms plugin before version 5.0.07 contains a stored cross-site scripting vulnerability in form labels that could be exploited by users with high-level privileges. The plugin failed to properly sanitize and escape label content, enabling attackers to inject malicious scripts even in environments where the unfiltered_html capability was restricted. This flaw was resolved in version 5.0.07 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.