PT-2023-16545 · WordPress · Formidable Forms

Daniel Ruf

·

Published

2023-03-27

·

Updated

2025-02-19

·

CVE-2023-0816

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Formidable Forms WordPress plugin versions prior to 6.1
Description The issue allows IP Address spoofing and bypass of anti-spam protections by using several potentially untrusted headers to determine the client's IP address.
Recommendations For versions prior to 6.1, update to version 6.1 or later to resolve the issue.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2023-0816

Affected Products

Formidable Forms