CVE-2023-2877

Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.


We have discovered 14,634 live websites that are affected by CVE-2023-2877.

Test my site




Affected Software

Product  Formidable Forms
Category Wordpress Plugins
Vulnerable Domains14,634 live websites (22.70% of Formidable Forms install base)
Vulnerable Versions
  • from 0 before 6.3.1
Vulnerable Versions Count243 versions ( 84.08% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Jun 27, 2023
  • Updated - Dec 3, 2024

Credits

  • Alex Sanford (finder)
  • WPScan (coordinator)

CVE-2023-2877 usage by Country

United States6,391 websites



Germany1,224 websites
France1,133 websites
GB885 websites
Netherlands442 websites
Sweden406 websites
Australia394 websites
Canada388 websites
Italy293 websites
Spain268 websites

CVE-2023-2877 usage by TLD

.com6,870 websites
.co.uk818 websites
.org680 websites
.de534 websites
.com.au492 websites
.fr488 websites
.nl471 websites
.ca375 websites
.se305 websites
.net274 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-2877

Top websites that are affected by CVE-2023-2877. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.ru Russia**,***
*******************.org United States**,***
**************.org United States**,***
*******.com France**,***
***************.com United States**,***
**.org United States**,***
***************.nyc United States**,***
*******.com United States***,***
**********.com United States***,***
*******.ch Switzerland***,***
See full domain list

FAQ

CVE-2023-2877 is Incorrect Authorization in Formidable Forms
A total of 14,634 websites have been identified as vulnerable to CVE-2023-2877, discovered through global website indexing conducted by WebTechSurvey.
Formidable Forms is susceptible to CVE-2023-2877 vulnerability.
Formidable Forms versions before 6.3.1 are vulnerable to CVE-2023-2877.
Version 6.3.1 of Formidable Forms addresses the CVE-2023-2877 security vulnerability.