Input validation vulnerability in Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder 6.7

The Formidable Forms plugin for WordPress has a security vulnerability that could allow unauthenticated users to inject HTML code into form fields in versions up to and including 6.7. If an administrator views the form data in the Entries View Page, the injected HTML code could be rendered, which could either lead to the defacement of the admin area or cause a redirection to a malicious website.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.