Skip to content
Noroxi

formassembly records

3 published records for vendor formassembly.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
66.7%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24
  2. 25

Bar: total · dark part: CISA KEV.

Attack profile

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

3 records
  • WordPress WP-FormAssembly plugin <= 2.0.5 - Auth. Arbitrary File Read vulnerability

    MediumCVSS 6.5No exploitEPSS 1%

    formassembly / drew buschhorn · wp-formassemblyApr 24, 2024

  • WordPress WP-FormAssembly plugin <= 2.0.10 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    formassembly / drew buschhorn · wp-formassemblyApr 18, 2024

  • WP-FormAssembly <= 2.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    MediumCVSS 5.4No exploitEPSS 0%

    formassembly · wp-formassemblyFeb 18, 2025