Plugin Vulnerability Hub
Plugin 23 known issues Latest disclosed Mar 12, 2026

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder (`formidable`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-2888, CVE-2026-2890 and CVE-2024-11188, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
23
High or Critical
9
Patch Coverage
100%
Last Updated
Mar 13, 2026
Related Security Guides

Use these guides while reviewing Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
21
1. Match the Package
Confirm the installed WordPress plugin slug is formidable before acting on any CVE from this cluster.
2. Sort by Severity
Start with 9 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
23 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
19
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2023-1405
Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection
Vulnerability Versions up to 6.1.2 6.2 CVSS 9.8
CVE-2019-15780
Formidable Form Builder <= 4.02 - PHP Object Injection
Vulnerability Versions before 4.02.01 4.02.01 CVSS 9.8
CVE-2021-24884
Formidable Form Builder <= 4.09.04 - Unauthenticated Stored Cross-Site Scripting
Remote Code Execution Versions before 4.09.05 4.09.05 CVSS 9.6
CVE-2014-9309
Formidable Form Builder <= 1.07.11 - SQL Injection
SQL Injection Versions up to 1.07.11 2.0 CVSS 8.8
CVE-2017-20192
Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting
Stored Cross-Site Scripting Versions before 2.05.03 2.05.03 CVSS 8.3
CVE-2026-2890
Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrit...
Vulnerability Versions up to 6.28 6.29 CVSS 7.5
CVE-2023-24419
Formidable Form Builder <= 5.5.6 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions up to 5.5.6 5.5.7 CVSS 7.1
CVE-2023-6830
Formidable Forms <= 6.7 - HTML Injection
Cross-Site Scripting Versions up to 6.7 6.7.1 CVSS 6.5
CVE-2023-1405 Critical 6.2
CVE-2023-1405 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerability

Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection

CVE-2019-15780 Critical 4.02.01
CVE-2019-15780 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerability

Formidable Form Builder <= 4.02 - PHP Object Injection

CVE-2021-24884 Critical 4.09.05
CVE-2021-24884 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Remote Code Execution

Formidable Form Builder <= 4.09.04 - Unauthenticated Stored Cross-Site Scripting

CVE-2014-9309 High 2.0
CVE-2014-9309 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder SQL Injection

Formidable Form Builder <= 1.07.11 - SQL Injection

CVE-2017-20192 High 2.05.03
CVE-2017-20192 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Stored Cross-Site Scripting

Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting

CVE-2026-2890 High 6.29
CVE-2026-2890 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Vulnerability

Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse

CVE-2023-24419 High 5.5.7
CVE-2023-24419 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Cross-Site Request Forgery

Formidable Form Builder <= 5.5.6 - Cross-Site Request Forgery

CVE-2023-6830 Medium 6.7.1
CVE-2023-6830 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Cross-Site Scripting

Formidable Forms <= 6.7 - HTML Injection

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
23 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
4 critical and 5 high severity findings.
Recent CVEs
CVE-2026-2888, CVE-2026-2890 and CVE-2024-11188
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2024-11188 Medium Patch path listed

CVE-2024-11188: Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via t...

Published
Nov 22, 2024
Patch Status
6.16.2
Known Vulnerabilities

Reports for Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-2888
CVE-2026-2888: Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter

The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all versions up to, and including, 6.28. This is due to the `frm_strp_amount` AJAX handler (`update_intent_ajax`) overwriting the global `$_POST` data with attacker-c...

Published
Mar 12, 2026
Patched Release
6.29
Affected Versions
Versions up to 6.28
Next Step
Update to 6.29 or newer if supported.
Plugin High Patched: Yes CVE-2026-2890
CVE-2026-2890: Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse

The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and including, 6.28. This is due to the Stripe Link return handler (`handle_one_time_stripe_link_return_url`) marking payment records as complete based solely on the Strip...

Published
Mar 12, 2026
Patched Release
6.29
Affected Versions
Versions up to 6.28
Next Step
Update to 6.29 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-11188
CVE-2024-11188: Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the Custom HTML Form parameters in all versions up to, and including, 6.16.1.2 due to insuf...

Published
Nov 22, 2024
Patched Release
6.16.2
Affected Versions
Versions up to 6.16.1.2
Next Step
Update to 6.16.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9768
CVE-2024-9768: Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.14 - Authenticated (Admin+) Stored Cross-Site Scripting

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 6.14 due to insufficient input sanitization and outp...

Published
Oct 31, 2024
Patched Release
6.14.1
Affected Versions
Versions up to 6.14
Next Step
Update to 6.14.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-6725
CVE-2024-6725: Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ parameter in all versions up to, and including, 6.11.1 due to insufficient input sanitization...

Published
Jul 30, 2024
Patched Release
6.11.2
Affected Versions
Versions up to 6.11.1
Next Step
Update to 6.11.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-0660
CVE-2024-0660: Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2. This is due to missing or incorrect nonce validation on the update_setti...

Published
Jan 26, 2024
Patched Release
6.8
Affected Versions
Versions up to 6.7.2
Next Step
Update to 6.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6830
CVE-2023-6830: Formidable Forms <= 6.7 - HTML Injection

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject arbitrary HTML code into form fields. When the form data is viewed by an administrator in the Entries View Pa...

Published
Jan 08, 2024
Patched Release
6.7.1
Affected Versions
Versions up to 6.7
Next Step
Update to 6.7.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6842
CVE-2023-6842: Formidable Forms <= 6.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name field label and description field label parameter in all versions up to 6.7 (inclusive) due to insuffic...

Published
Jan 08, 2024
Patched Release
6.7.1
Affected Versions
Versions up to 6.7
Next Step
Update to 6.7.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-2877
CVE-2023-2877: Formidable Forms <= 6.3 - Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation

The Formidable Forms plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the screen_page() and can_install_addon_api() functions in versions up to, and including, 6.3. This makes it possible for auth...

Published
May 31, 2023
Patched Release
6.3.1
Affected Versions
Versions before 6.3.1
Next Step
Update to 6.3.1 or newer if supported.
Plugin Critical Patched: Yes CVE-2023-1405
CVE-2023-1405: Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection

The Formidable Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.2 via deserialization of untrusted input from form submissions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulne...

Published
Apr 06, 2023
Patched Release
6.2
Affected Versions
Versions up to 6.1.2
Next Step
Update to 6.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-0816
CVE-2023-0816: Formidable Forms <= 6.0.1 - IP Spoofing via HTTP header

The Formidable Forms plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 6.0.1 due to a reliance on various untrusted headers (e.g., 'Client-Ip', 'CF-CONNECTING-IP', etc.) to retrieve the IP address of a client performing a form submission. This ma...

Published
Mar 06, 2023
Patched Release
6.1
Affected Versions
Versions up to 6.0.1
Next Step
Update to 6.1 or newer if supported.
Plugin High Patched: Yes CVE-2023-24419
CVE-2023-24419: Formidable Form Builder <= 5.5.6 - Cross-Site Request Forgery

The Formidable Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.5.6. This is due to missing or incorrect nonce validation on the 'destroy' function. This makes it possible for unauthenticated attackers to delete for...

Published
Feb 01, 2023
Patched Release
5.5.7
Affected Versions
Versions up to 5.5.6
Next Step
Update to 5.5.7 or newer if supported.