VYPR
Unrated severityNVD Advisory· Published Feb 28, 2023· Updated Apr 28, 2026

WordPress Formidable Forms Plugin <= 5.5.6 is vulnerable to Cross Site Request Forgery (CSRF)

CVE-2023-24419

Description

Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in Formidable Forms plugin versions up to 5.5.6 allows attackers to perform unauthorized actions.

Vulnerability

The Formidable Forms plugin for WordPress contains a Cross-Site Request Forgery (CSRF) vulnerability in versions up to and including 5.5.6. The flaw exists in the plugin's request handling, allowing an attacker to forge requests on behalf of an authenticated administrator without their consent.

Exploitation

An attacker can exploit this vulnerability by tricking an authenticated administrator into clicking a malicious link or visiting a crafted page. The attacker does not need authentication, but the victim must have an active session in the WordPress admin area. The attacker can then perform actions that the victim is authorized to execute, such as modifying forms, settings, or other plugin operations.

Impact

Successful exploitation enables the attacker to perform unauthorized actions within the Formidable Forms plugin, potentially leading to data manipulation, form deletion, or other administrative changes. The impact is limited to the privileges of the victim user.

Mitigation

The vulnerability is fixed in versions after 5.5.6. Users should update to the latest version of the plugin. As of the publication date, the current version is 6.30 [1]. No workarounds are documented in the available references.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.