CVE-2023-1405: Formidable Forms < 6.2 - Unauthenticated PHP Object Injection
Published Jan 16, 2024
·Updated
The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.
Affected Software
1 affected component
Strategy11 Formidable Forms Wordpress<6.2
Event History
Jan 16, 2024
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1405?
CVE-2023-1405 is classified as a high severity vulnerability due to its potential for PHP Object Injection.
2
How do I fix CVE-2023-1405?
To fix CVE-2023-1405, update the Formidable Forms plugin to version 6.2 or later.
3
Who is affected by CVE-2023-1405?
CVE-2023-1405 affects users of the Formidable Forms WordPress plugin prior to version 6.2.
4
Can anonymous users exploit CVE-2023-1405?
Yes, anonymous users could exploit CVE-2023-1405 due to the improper handling of user input.
5
What type of vulnerability is CVE-2023-1405?
CVE-2023-1405 is categorized as a PHP Object Injection vulnerability.