Executive brief
Formidable Forms is a popular WordPress plugin for creating custom forms. The plugin before version 6.35 fails to properly validate who can modify the "updated_by" field on form entries, allowing unauthenticated users to inject HTML markup that bypasses the plugin's sanitization filters. This enables attackers to display malicious content to administrators viewing form submissions and falsely attribute entries to legitimate users.
Technical details
The vulnerability is a stored content injection flaw in Formidable Forms prior to version 6.35. The plugin relies on the "updated_by" identifier to decide whether to strip HTML tags from entry values; however, it does not restrict who can set this identifier. An unauthenticated attacker can exploit this by crafting a form submission with a modified "updated_by" parameter, causing the plugin to store HTML markup that would normally be sanitized. When an administrator views the entry in the admin panel, the injected markup is rendered. The flaw also allows attribution spoofing, making malicious submissions appear to come from legitimate administrators.
Affected products
- Strategy11 Formidable Forms before 6.35
Timeline
- 2026-09-14: disclosed
- 2026-09-16: advisory
- 2026: patched: Fixed in version 6.35