CVE-2023-2877Active Exploitation(strategy11 / formidable_forms)

LOWCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for strategy11 formidable_forms systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

3.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • formidable_forms

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
formidable_forms

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-27: 1Active Exploitation · 2026-03-27: 1Technical Details · 2026-03-27: 103-27
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • @pedri77@pedri77
    Active Exploitation

    GreyNoise researchers have observed exploit attempts targeting the remote code execution vulnerability CVE-2023-28771 in Zyxel devices. On June 16, GreyNoise researchers detected exploit attempts targeting CVE-2023-2877... https://f.mtr.cool/seikawkhxh

    Post summary

    GreyNoise reported active exploit attempts against Zyxel's CVE-2023-28771 RCE vulnerability, but no PoC, exploit code, or mitigation details were provided.

    0000064
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrategy11formidable_forms-wordpress-

Explore more