CVE-2023-0816
PoC —CVSS 3.1
6.5 medium
EPSS
<1%p41
Published
()
Modified
Description
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
- Vendors
- strategy11
- Products
- formidable form builder
- Ecosystems
- WordPress
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.