← WordPress Vulnerabilities
WordPress security by component

Funnelforms Free

Funnelforms Free is a WordPress component with 11 published CVE records in this archive. The latest tracked vulnerability was published Nov 22, 2023; the highest CVE/CNA score is 6.5.

Plugin slug: funnelforms

CVE-2023-5419: Funnelforms Free: A security weakness

Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedNov 22, 2023
Safe version guidanceSee mitigation notes
Safe version
Nov 22, 2023 CVE-2023-5419
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5417
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5416
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5415
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5411
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5387
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5386
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD4.3
Nov 22, 2023 CVE-2023-5385
Funnelforms Free: A security weakness
Funnelforms Free is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5383
Funnelforms Free: Cross-site request forgery
Funnelforms Free is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Nov 22, 2023 CVE-2023-5382
Funnelforms Free: Cross-site request forgery
Funnelforms Free is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.5
NVD4.3
Oct 16, 2023 CVE-2023-4950
Interactive Contact Form and Multi Step Form Builder: Cross-site scripting
Interactive Contact Form and Multi Step Form Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1