Description
WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass plugin's anti-spam protections. WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder version 6.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:A281F63F-E295-4666-8A08-01B23CD5A744
https://plugins.svn.wordpress.org/formidable/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin AddSearch Cross-Site Scripting (1.1.0)
PHP Other Vulnerability (CVE-2006-2660)
Squid Insufficient Verification of Data Authenticity Vulnerability (CVE-2016-4554)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-7061)
WordPress Plugin Dropdown and scrollable Text Cross-Site Scripting (2.0)