Black Friday Deals 40% OFF

Days
Hours
Minutes

Input validation vulnerability in Flo Forms – Easy Drag & Drop Form Builder 1.0.43

The Flo Forms plugin for WordPress has a security vulnerability where malicious code can be uploaded through SVG files. This can happen because the plugin allows these file uploads without properly checking the content. This means that someone without authorization could upload a file containing harmful code, which could then be executed by an administrator who views it in the WordPress admin interface. This could potentially lead to the entire website being compromised.

Detected in:

Flo Forms – Easy Drag & Drop Form Builder open vulnerable versions: >= * <= 1.0.43

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.