Vulnerabilities
Formidable Forms 1.07.11 Blind SQL Injection
`FrmFormsController
26-01-2016
2 MIN READ
Vulnerabilities
`FrmFormsController
2 MIN READ
Vulnerabilities
Prevent username enumeration
5 MIN READ
Vulnerabilities
$whereClause and $whereClauseT and $whereClauseW and $whereClause2W are not escaped.
3 MIN READ
Vulnerabilities
Inside almost all wp_ajax function there is no privilege check.
1 MIN READ
Vulnerabilities
Every registered user can access plugin admin interface.
1 MIN READ
Vulnerabilities
$_POST['poll_id'] is not escaped properly.
2 MIN READ
Vulnerabilities
By default it's possible to upload .html files. So we can put XSS there.
1 MIN READ
Vulnerabilities
Nonce token is not checked inside install_new_favicon() function.
1 MIN READ