Description
WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass plugin's anti-spam protections. WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder version 6.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:A281F63F-E295-4666-8A08-01B23CD5A744
https://plugins.svn.wordpress.org/formidable/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Contentboxes Cross-Site Scripting (1.1)
Liferay DXP URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2024-25608)
Magento Improper Input Validation Vulnerability (CVE-2019-7899)
Drupal Resource Management Errors Vulnerability (CVE-2014-5265)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-22881)