The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with form editing permissions and Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
We have discovered 25,400 live websites that are affected by CVE-2024-6725.
Product | ![]() |
Category | Wordpress Plugins |
Vulnerable Domains | 25,400 live websites (39.40% of Formidable Forms install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 272 versions ( 94.12% of all versions) |
![]() | 12,027 websites |
![]() | 2,038 websites |
![]() | 1,850 websites |
![]() | 1,433 websites |
![]() | 777 websites |
![]() | 635 websites |
![]() | 601 websites |
![]() | 548 websites |
![]() | 470 websites |
![]() | 459 websites |
.com | 12,354 websites |
.org | 1,308 websites |
.co.uk | 1,281 websites |
.de | 899 websites |
.nl | 820 websites |
.com.au | 812 websites |
.fr | 791 websites |
.ca | 674 websites |
.net | 488 websites |
.se | 431 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
************.**.**.uk | ![]() | **,*** | |
********.**.**.uk | ![]() | **,*** | |
**************.com | ![]() | **,*** | |
********.ru | ![]() | **,*** | |
*******************.org | ![]() | **,*** | |
**************.org | ![]() | **,*** | |
****.**.uk | ![]() | **,*** | |
*******.com | ![]() | **,*** | |
***************.com | ![]() | **,*** |
FAQ