Segurium Research Advisories formidable

Formidable Forms 6.33.1 and earlier: Cross-site scripting

high Cross-site scripting

Formidable Forms 6.34 adds a FrmHtmlSanitizer class that cleans href and src values before entry data reaches the screen. Releases up to 6.33.1 checked those URLs while they were still entity-encoded.

Plugin
Formidable Forms formidable
Affected versions
6.33.1 and earlier
Fixed in
6.34
Class
Cross-site scripting
Severity
high Segurium Research assessment. No CVSS score published yet.
CVE
None assigned at the time of writing
Installs
300,000 active
Patch released
Sources
Read the teardown What the release changed, how the bug worked, and what to check on a site that ran the affected version.

Segurium Research writes these up from public source after the fix has shipped. We do not scan or probe third-party sites, and no teardown here carries a working exploit. Segurium itself is a WordPress malware scanner on the official directory at wordpress.org/plugins/segurium/.