Input validation vulnerability in Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free 3.7.4.1

The Funnelforms Free plugin for WordPress, which allows users to create interactive contact forms and multi-step forms, has been found to have a security vulnerability in all versions up to 3.7.4.1. This vulnerability, known as PHP Object Injection, occurs when untrusted input is deserialized, allowing authenticated attackers with Contributor-level access or higher to inject a PHP Object. While there is no known fix for this vulnerability, if the target system has additional plugins or themes installed with a POP chain, it could potentially allow the attacker to delete files, access sensitive information, or run code.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.