Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.7.4.1

    Open

    The Funnelforms Free plugin for WordPress, which allows users to create interactive contact forms and multi-step forms, has been found to have a security vulnerability in all versions up to 3.7.4.1. ...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.7.3.2

    Fixed

    The Funnelforms Free plugin for WordPress, which is used to create contact forms and multi-step forms, has a security issue that could result in the loss of data. This vulnerability, present in all v...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.7.3.2

    Fixed

    The Funnelforms Free plugin for WordPress, which allows users to create interactive contact forms and multi-step forms, is at risk of having its data changed without permission. This is because a key...

    Read More
  • Input validation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.7.3.2

    Fixed

    The Funnelforms Free plugin for WordPress has a problem that could make it vulnerable to attacks. This is because it does not check the type of files being uploaded in the 'af2_add_font' function in ...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.7.3.2

    Fixed

    A popular plugin called Funnelforms Free for WordPress has a security issue where any file can be deleted without proper validation. This means that someone who is not authorized can delete important...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress is vulnerable to a security issue. In versions up to and including 3.4, there is a missing capability check on the fnsf_copy_posts function. This means that ...

    Read More
  • Input validation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress is vulnerable to an attack called Cross-Site Request Forgery. Versions up to and including 3.4 of this plugin are affected. This is because there is either n...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress is not secure in versions up to 3.4. An attacker with a subscriber-level permission or higher can change the dark mode plugin setting without authorization. ...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized changes to data. This means that attackers who have a subscriber-level account or higher can delete categories in versions up t...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress has a security issue in versions up to and including 3.4. This issue means that an attacker with subscriber-level permissions and above can modify certain pa...

    Read More
  • Input validation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects versions up to and including 3.4. It is caused by incorrect o...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress has a security flaw in versions 3.4 and lower. This flaw allows users with the minimum permission level of "subscriber" to add new categories to the plugin w...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress has a security issue that affects versions up to 3.4. Any user with subscriber-level permission or higher can send test emails to any email address without p...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress is vulnerable to unauthorized changes of data. This means that if someone has access to your website, they can delete posts, including posts that were writte...

    Read More
  • Access violation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress had a security vulnerability in versions up to, and including, 3.4. This vulnerability made it possible for people with certain permissions to change the Fun...

    Read More
  • Input validation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.4

    Fixed

    The Funnelforms Free plugin for WordPress has a security vulnerability which could allow unauthenticated attackers to inject malicious web scripts into pages. This affects versions up to and includin...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More