First published: Tue Jan 16 2024(Updated: )
The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Formidable Forms | <6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1405 is classified as a high severity vulnerability due to its potential for PHP Object Injection.
To fix CVE-2023-1405, update the Formidable Forms plugin to version 6.2 or later.
CVE-2023-1405 affects users of the Formidable Forms WordPress plugin prior to version 6.2.
Yes, anonymous users could exploit CVE-2023-1405 due to the improper handling of user input.
CVE-2023-1405 is categorized as a PHP Object Injection vulnerability.