CVE-2023-0816
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
- Affected products
- Formidable Forms
- strategy11 Formidable Form Builder
- < 6.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.5% (41th percentile)
- Weakness
- CWE-290
- NVD status
- Modified
- Published
- 2023-03-27
CVE-2023-0816 at NVD
2 known exploits for CVE-2023-0816
Proof-of-concept code and exploit modules indexed by Sploitus