CVE · Critical

CVE-2021-24884 — Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 4.09.05

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24884 Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More [formidable] < 4.09.05 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Critical 9.6 < 4.09.05 4.09.05 2021-01-28

CVE-2021-24884

Formidable Forms WordPress plugin versions before 4.09.05 contain an HTML injection vulnerability in the "data-frmverify" tag on the entry inspection page that fails to properly sanitize user input. An unauthenticated attacker could inject malicious HTML tags such as audio, video, img, a, and button elements to create deceptive links that execute JavaScript when clicked by authenticated users. When combined with CSRF attacks, this vulnerability could enable attackers to perform unauthorized actions including password changes, account theft, arbitrary form submissions leading to remote code execution, or modification of PHP code if the victim has administrative privileges.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.