Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 22%
from disclosure to weapon1 days
Published on NVDJun 27
1st PoC+1d
VulnCheckJan 10
exploitation probability
22%top 3% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
Affected products
Unknown · Formidable Formspublic PoCs found — 1
vulncheckvulncheck.com/xdb/4fad991828e1unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.