← back
CVE-2023-2877observed exploitation

Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actepss 22%
from disclosure to weapon1 days
Published on NVDJun 27
1st PoC+1d
VulnCheckJan 10
exploitation probability
22%top 3% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.