Description
WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently bypass plugin's anti-spam protections. WordPress Plugin Formidable Forms-Contact Form, Survey, Quiz, Calculator & Custom Form Builder version 6.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 6.1 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:A281F63F-E295-4666-8A08-01B23CD5A744
https://plugins.svn.wordpress.org/formidable/trunk/readme.txt
Related Vulnerabilities
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2017-2608)
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-7537)
Grafana Cleartext Storage of Sensitive Information Vulnerability (CVE-2020-12458)
SugarCRM Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-17305)
WordPress Plugin Login or Logout Menu Item Security Bypass (1.1.1)