ZeroHour

CVE-2023-0816

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p41
Published
()
Modified
Description

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

Vendors
strategy11
Products
formidable form builder
Ecosystems
WordPress
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.