CVE-2023-1405

Formidable Forms < 6.2 - Unauthenticated PHP Object Injection

The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.


We have discovered 14,125 live websites that are affected by CVE-2023-1405.

Test my site




Affected Software

Product  Formidable Forms
Category Wordpress Plugins
Vulnerable Domains14,125 live websites (21.91% of Formidable Forms install base)
Vulnerable Versions
  • from 0 before 6.2
Vulnerable Versions Count238 versions ( 82.35% of all versions)


Common Weakness Enumeration

CWE-502 Deserialization of Untrusted Data



Details

  • Published - Jan 16, 2024
  • Updated - Oct 22, 2024

Credits

  • Nguyen Huu Do (finder)
  • WPScan (coordinator)

CVE-2023-1405 usage by Country

United States6,138 websites



Germany1,180 websites
France1,107 websites
GB865 websites
Netherlands431 websites
Sweden405 websites
Australia377 websites
Canada375 websites
Italy285 websites
Spain257 websites

CVE-2023-1405 usage by TLD

.com6,605 websites
.co.uk798 websites
.org661 websites
.de513 websites
.fr476 websites
.com.au467 websites
.nl458 websites
.ca352 websites
.se304 websites
.it270 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-1405

Top websites that are affected by CVE-2023-1405. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.ru Russia**,***
*******************.org United States**,***
**************.org United States**,***
*******.com France**,***
***************.com United States**,***
**.org United States**,***
***************.nyc United States**,***
*******.com United States***,***
**********.com United States***,***
*******.ch Switzerland***,***
See full domain list

FAQ

CVE-2023-1405 is Deserialization of Untrusted Data in Formidable Forms
A total of 14,125 websites have been identified as vulnerable to CVE-2023-1405, discovered through global website indexing conducted by WebTechSurvey.
Formidable Forms is susceptible to CVE-2023-1405 vulnerability.
Formidable Forms versions before 6.2 are vulnerable to CVE-2023-1405.
Version 6.2 of Formidable Forms addresses the CVE-2023-1405 security vulnerability.