« Back to list

Strategy11

Strategy11 Formidable Forms: vulnerabilities and CVEs

Strategy11 Formidable Forms has 14 published vulnerabilities, 6 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs14
Last 12 months6
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-19857Medium (4.8)0.19%—Sep 16, 2026
The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing…
CVE-2026-85641Medium (4.3)0.14%—Sep 16, 2026
The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies on that identifier when deciding whether to strip HTML from stored…
CVE-2026-18331High (7.2)0.41%—Aug 26, 2026
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'frm_user_id' parameter in all versions up to, and…
CVE-2026-11361Medium (5.9)0.18%—Aug 6, 2026
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid…
CVE-2026-2890High (7.5)0.51%—Mar 13, 2026
The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`)…
CVE-2026-2888Medium (5.3)0.44%—Mar 13, 2026
The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler…
CVE-2022-45806Critical (9.8)0.52%—Dec 13, 2024
Missing Authorization vulnerability in Strategy11 Form Builder Team Formidable Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Formidable Forms: from n/a through 5.5.4.
CVE-2024-11188Medium (6.1)0.40%—Nov 23, 2024
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form…
CVE-2024-9768Medium (4.8)0.43%—Nov 21, 2024
The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…
CVE-2024-6725Medium (5.4)0.37%—Jul 31, 2024
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to,…
CVE-2024-23522Medium (6.1)0.34%—May 17, 2024
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder Team Formidable Forms allows Code Injection.This issue affects Formidable Forms: from n/a through…
CVE-2024-0660Medium (4.3)0.21%—Feb 5, 2024
The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due…
CVE-2023-1405High (7.5)0.70%—Jan 16, 2024
The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
CVE-2023-2877High (8.8)22%—Jun 27, 2023
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to…

Other products by Strategy11