The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Page, the injected HTML code is rendered, potentially leading to admin area defacement or redirection to malicious websites.
History

Tue, 03 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-01-09T06:41:00.765Z

Updated: 2025-06-03T14:33:09.789Z

Reserved: 2023-12-14T21:09:20.081Z

Link: CVE-2023-6830

cve-icon Vulnrichment

Updated: 2024-08-02T08:42:07.656Z

cve-icon NVD

Status : Modified

Published: 2024-01-09T07:15:13.223

Modified: 2025-06-03T15:15:52.143

Link: CVE-2023-6830

cve-icon Redhat

No data.