Formidable
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15780 | Cri | 0.64 | 9.8 | 0.02 | Aug 29, 2019 | The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | ||
| CVE-2026-18331 | Hig | 0.47 | 7.2 | 0.00 | Aug 26, 2026 | The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization… |
- risk 0.64cvss 9.8epss 0.02
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
- risk 0.47cvss 7.2epss 0.00
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and including, 6.33.1 due to insufficient input sanitization…