VYPR

Formidable Form Builder

by WordPress

CVEs (4)

  • CVE-2017-20192HigOct 16, 2024
    risk 0.54cvss 8.3epss 0.01

    The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2017-20194MedOct 16, 2024
    risk 0.35cvss 5.3epss 0.01

    The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

  • CVE-2021-24608MedOct 25, 2021
    risk 0.31cvss 4.8epss 0.01

    The Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress plugin before 5.0.07 does not sanitise and escape its Form's Labels, allowing high privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is…

  • CVE-2021-24884CriOct 25, 2021
    risk 0.00cvss 9.6epss 0.03

    The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…