Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 23 vulnerability records associated with Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More, published between 2016 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

23Total records
4Critical
5High
14Medium
0Low
0Informational
23Patched records
0Currently marked unpatched
2016-01-26First disclosure
2026-03-12Latest disclosure
19 of 23CVE coverage

Use this history

Check and watch Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More.

A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.

Year-by-Year Timeline

YearRecordsRelative volume
201622 records
201744 records
201911 records
202122 records
202222 records
202344 records
202466 records
202622 records

Severity Breakdown

SeverityRecordsShare
Critical417.4%
High521.7%
Medium1460.9%

Vulnerability-Type Breakdown

Cross-Site Scripting

9 records39.1%

First: 2017. Latest: 2024.

Other

4 records17.4%

First: 2019. Latest: 2023.

CSRF

3 records13%

First: 2022. Latest: 2024.

Missing Authorization

3 records13%

First: 2023. Latest: 2026.

SQL Injection

2 records8.7%

First: 2016. Latest: 2017.

Privilege Escalation

1 record4.3%

First: 2016. Latest: 2016.

Information Disclosure

1 record4.3%

First: 2017. Latest: 2017.

Patch Status

Patched
23
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 6.29
  • 6.16.2
  • 6.14.1
  • 6.11.2
  • 6.8
  • 6.7.1
  • 6.3.1
  • 6.2
  • 6.1
  • 5.5.7
  • 5.5.5
  • 5.0.07
  • 4.09.05
  • 4.02.01
  • 2.05.03
  • 2.0.22
  • 2.0

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-6.28Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' ParameterMarch 12, 20266.29Medium
*-6.28Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent ReuseMarch 12, 20266.29High
*-6.16.1.2Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form ParameterNovember 22, 20246.16.2Medium
*-6.14Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.14 - Authenticated (Admin+) Stored Cross-Site ScriptingOctober 31, 20246.14.1Medium
*-6.11.1Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site ScriptingJuly 30, 20246.11.2Medium
*-6.7.2Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site ScriptingJanuary 26, 20246.8Medium
*-6.7Formidable Forms <= 6.7 - HTML InjectionJanuary 8, 20246.7.1Medium
*-6.7Formidable Forms <= 6.7 - Authenticated (Administrator+) Stored Cross-Site ScriptingJanuary 8, 20246.7.1Medium
[*, 6.3.1)Formidable Forms <= 6.3 - Authenticated (Subscriber+) Arbitrary Plugin Installation and ActivationMay 31, 20236.3.1Medium
*-6.1.2Formidable Forms <= 6.1.2 - Unauthenticated PHP Object InjectionApril 6, 20236.2Critical
*-6.0.1Formidable Forms <= 6.0.1 - IP Spoofing via HTTP headerMarch 6, 20236.1Medium
*-5.5.6Formidable Form Builder <= 5.5.6 - Cross-Site Request ForgeryFebruary 1, 20235.5.7High
*-5.5.4Formidable Forms <= 5.5.4 - Authenticated (Admin+) Server-Side Request ForgeryDecember 16, 20225.5.5Medium
*-5.5.4Formidable Form Builder <= 5.5.4 - Cross-Site Request ForgeryDecember 16, 20225.5.5Medium
[*, 5.0.07)Formidable Form Builder <= 5.0.06 - Admin+ Stored Cross-Site ScriptingOctober 6, 20215.0.07Medium
[*, 4.09.05)Formidable Form Builder <= 4.09.04 - Unauthenticated Stored Cross-Site ScriptingJanuary 28, 20214.09.05Critical
[*, 4.02.01)Formidable Form Builder <= 4.02 - PHP Object InjectionAugust 9, 20194.02.01Critical
[*, 2.05.03)Formidable Form Builder < 2.05.03 - Reflected Cross-Site ScriptingNovember 13, 20172.05.03Medium
[*, 2.05.03)Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site ScriptingNovember 13, 20172.05.03High
[*, 2.05.03)Formidable Form Builder < 2.05.03 - SQL InjectionNovember 13, 20172.05.03High
[*, 2.05.03)Formidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureNovember 12, 20172.05.03Medium
*-2.0.21Formidable Form Builder <= 2.0.21 - Missing Authorization ChecksFebruary 16, 20162.0.22Critical
*-1.07.11Formidable Form Builder <= 1.07.11 - SQL InjectionJanuary 26, 20162.0High

Selected source records

Latest Records

MediumCVE-2026-2888

Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter

Published: March 12, 2026

Affected versions
*-6.28
Patched versions
6.29
Original Wordfence record
HighCVE-2026-2890

Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse

Published: March 12, 2026

Affected versions
*-6.28
Patched versions
6.29
Original Wordfence record
MediumCVE-2024-11188

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter

Published: November 22, 2024

Affected versions
*-6.16.1.2
Patched versions
6.16.2
Original Wordfence record
MediumCVE-2024-9768

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.14 - Authenticated (Admin+) Stored Cross-Site Scripting

Published: October 31, 2024

Affected versions
*-6.14
Patched versions
6.14.1
Original Wordfence record
MediumCVE-2024-6725

Formidable Forms <= 6.11.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Published: July 30, 2024

Affected versions
*-6.11.1
Patched versions
6.11.2
Original Wordfence record
MediumCVE-2024-0660

Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Published: January 26, 2024

Affected versions
*-6.7.2
Patched versions
6.8
Original Wordfence record
MediumCVE-2023-6842

Formidable Forms <= 6.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

Published: January 8, 2024

Affected versions
*-6.7
Patched versions
6.7.1
Original Wordfence record
MediumCVE-2023-6830

Formidable Forms <= 6.7 - HTML Injection

Published: January 8, 2024

Affected versions
*-6.7
Patched versions
6.7.1
Original Wordfence record

Highest-Severity Records

CriticalCVE-2023-1405

Formidable Forms <= 6.1.2 - Unauthenticated PHP Object Injection

Published: April 6, 2023

Affected versions
*-6.1.2
Patched versions
6.2
Original Wordfence record
CriticalCVE-2019-15780

Formidable Form Builder <= 4.02 - PHP Object Injection

Published: August 9, 2019

Affected versions
[*, 4.02.01)
Patched versions
4.02.01
Original Wordfence record
CriticalCVE-2021-24884

Formidable Form Builder <= 4.09.04 - Unauthenticated Stored Cross-Site Scripting

Published: January 28, 2021

Affected versions
[*, 4.09.05)
Patched versions
4.09.05
Original Wordfence record
Critical

Formidable Form Builder <= 2.0.21 - Missing Authorization Checks

Published: February 16, 2016

Affected versions
*-2.0.21
Patched versions
2.0.22
Original Wordfence record
HighCVE-2014-9309

Formidable Form Builder <= 1.07.11 - SQL Injection

Published: January 26, 2016

Affected versions
*-1.07.11
Patched versions
2.0
Original Wordfence record
High

Formidable Form Builder < 2.05.03 - SQL Injection

Published: November 13, 2017

Affected versions
[*, 2.05.03)
Patched versions
2.05.03
Original Wordfence record
HighCVE-2017-20192

Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting

Published: November 13, 2017

Affected versions
[*, 2.05.03)
Patched versions
2.05.03
Original Wordfence record
HighCVE-2026-2890

Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse

Published: March 12, 2026

Affected versions
*-6.28
Patched versions
6.29
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory