Formidable Form Builder <= 2.0.21 - Missing Authorization Checks
2016-02-16 00:00
James GolovichStrategic Overview
StatusPatched in 2.0.22
Affected PluginFormidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More
Affected Version
<= 2.0.21CVSS9.1Critical
CVE
N/AVulnerability Overview
The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.21. This is due to missing nonce and capability checks on the 'frm_fill_licenses' and 'frm_ajax' AJAX actions. This makes it possible for unauthenticated attackers to access leaked nonces and modify form fields.
Technical Analysis
REMEDIATION: Update to version 2.0.22, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C