CVE-2021-24884
Formidable Forms WordPress plugin versions before 4.09.05 contain an HTML injection vulnerability in the "data-frmverify" tag on the entry inspection page that fails to properly sanitize user input. An unauthenticated attacker could inject malicious HTML tags such as audio, video, img, a, and button elements to create deceptive links that execute JavaScript when clicked by authenticated users. When combined with CSRF attacks, this vulnerability could enable attackers to perform unauthorized actions including password changes, account theft, arbitrary form submissions leading to remote code execution, or modification of PHP code if the victim has administrative privileges.
Based on public CVE data (MITRE/NVD).