
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-24884 affects the Formidable Form Builder WordPress plugin versions before 4.09.05. The vulnerability is due to insufficient sanitization of the 'data-frmverify' tag for links in the web-based entry inspection page of affected systems, allowing unauthenticated attackers to perform HTML injection attacks (WPScan, NVD).
The vulnerability is classified as an Unauthenticated Stored Cross-Site Scripting (XSS) with a CVSS v3.1 base score of 9.6 (Critical). The issue stems from improper sanitization of HTML tags in the plugin, specifically affecting the 'data-frmverify' tag. This vulnerability is tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-352 (Cross-Site Request Forgery) (NVD).
A successful exploitation of this vulnerability, especially when combined with CSRF, could allow attackers to perform arbitrary actions with the privileges of the authenticated user. These actions include potential account takeover by changing passwords and the ability to submit malicious code through an authenticated user, potentially leading to Remote Code Execution if the authenticated user has permissions to edit WordPress PHP code (WPScan).
The vulnerability has been patched in version 4.09.05 of the Formidable Form Builder plugin. Users are strongly advised to update to this version or later to mitigate the risk (WPScan, GitHub Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."