PT-2024-16807 · WordPress · Formidable Forms
Michael Mazzolini
+1
·
Published
2024-11-22
·
Updated
2025-07-12
·
CVE-2024-11188
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress versions up to, and including, 6.16.1.2
Description
The issue is related to insufficient input sanitization and output escaping in the Custom HTML Form parameters, allowing unauthenticated attackers to inject arbitrary web scripts in pages. This can be achieved by tricking a user into performing an action, such as clicking on a link, which executes the injected script.
Recommendations
For versions up to, and including, 6.16.1.2, update to a version later than 6.16.1.2 to resolve the issue.
As a temporary workaround, consider restricting access to the Custom HTML Form parameters to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Formidable Forms