Description
WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass plugin's anti-spam protections. WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder version 6.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:A281F63F-E295-4666-8A08-01B23CD5A744
https://plugins.svn.wordpress.org/formidable/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin SP Project & Document Manager SQL Injection (2.5.3)
Jboss EAP CVE-2012-5626 Vulnerability (CVE-2012-5626)
WordPress Plugin News Element Elementor Blog Magazine Local File Inclusion (1.0.5)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17301)
concrete5 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-5107)