Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-0816

Description

The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.

POC

Reference

- https://wpscan.com/vulnerability/a281f63f-e295-4666-8a08-01b23cd5a744

Github

- https://github.com/20142995/nuclei-templates