Formidable Forms <= 6.0.1 - IP Spoofing via HTTP header
Strategic Overview
<= 6.0.1CVE-2023-0816Vulnerability Overview
The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a reliance on various untrusted headers (e.g., 'Client-Ip', 'CF-CONNECTING-IP', etc.) to retrieve the IP address of a client performing a form submission. This makes it possible for unauthenticated users to bypass the plugin's anti-spam protections.
Technical Analysis
REMEDIATION: Update to version 6.1, or a newer patched version --- IDENTIFIER: CWE-807 (Reliance on Untrusted Inputs in a Security Decision) The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C