The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
We have discovered 14,634 live websites that are affected by CVE-2023-2877.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 14,634 live websites (22.70% of Formidable Forms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 243 versions ( 84.08% of all versions) |
![]() | 6,391 websites |
![]() | 1,224 websites |
![]() | 1,133 websites |
![]() | 885 websites |
![]() | 442 websites |
![]() | 406 websites |
![]() | 394 websites |
![]() | 388 websites |
![]() | 293 websites |
![]() | 268 websites |
.com | 6,870 websites |
.co.uk | 818 websites |
.org | 680 websites |
.de | 534 websites |
.com.au | 492 websites |
.fr | 488 websites |
.nl | 471 websites |
.ca | 375 websites |
.se | 305 websites |
.net | 274 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.ru | ![]() | **,*** | |
*******************.org | ![]() | **,*** | |
**************.org | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
**.org | ![]() | **,*** | |
***************.nyc | ![]() | **,*** | |
*******.com | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
*******.ch | ![]() | ***,*** |
FAQ