Input validation vulnerability in Formidable Forms – Contact Form, Survey, Quiz, Calculator & Custom Form Builder 2.05.03

The Formidable Form Builder plugin for WordPress is vulnerable to an attack called SQL Injection. This attack can be used to access sensitive information from the database, and is present in versions of the plugin before 2.05.03. The problem is caused by the plugin not properly securing a parameter used in the shortcode ‘display-frm-data’, and not properly preparing an existing SQL query.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.