CVE-2023-0816: STRATEGY11 Formidable Form Builder
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
Affected products
- STRATEGY11 Formidable Form Builder: before 6.1 (fixed in 6.1)
Published 2023-03-27. Last modified 2026-06-17.