Strategy11 develops a focused set of WordPress plugins centered on directory listing, classified-ad, and form-building functionality, serving small-business and community websites. The vendor's vulnerability footprint, while concentrated in a narrow product portfolio, skews toward serious outcomes and frequently acquires public exploit code, reflecting the web-facing and user-input-heavy nature of directory and form plugins. The recurring exposure concentrates in products such as Formidable Forms and Business Directory Plugin and clusters persistently around input-handling weaknesses including cross-site scripting, SQL injection, cross-site request forgery, and untrusted deserialization—vulnerability classes endemic to web applications that parse user submissions and render dynamic content. Defenders should prioritize patching this vendor's plugins on internet-exposed WordPress sites, as these weakness classes are routinely weaponized in plugin-focused scanning campaigns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Strategy11 over time
Signals from CVEs in this vendor scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3254CRITICAL The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available | Oct 31, 2022 | 9.8 | 44 | NO | YES |
CVE-2023-2877HIGH The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user | Jun 27, 2023 | 8.8 | 38 | NO | NO |
CVE-2017-20192MEDIUM The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions be | Oct 16, 2024 | 6.1 | 32 | NO | YES |
CVE-2021-24884CRITICAL The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remot | Oct 25, 2021 | 9.6 | 31 | NO | NO |
CVE-2019-15780CRITICAL The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. | Aug 29, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-10013HIGH SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase paramet | Jan 13, 2015 | 7.5 | 30 | NO | YES |
CVE-2017-20194MEDIUM The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This make | Oct 16, 2024 | 5.3 | 29 | NO | YES |
CVE-2023-24419HIGH Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions. | Feb 28, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-24179HIGH The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a | May 6, 2021 | 8.8 | 26 | NO | NO |
CVE-2023-41801HIGH Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions. | Oct 6, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (29 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Strategy11.
Media articles that mention a CVE ID that affects a product developed by Strategy11 — matched by CVE ID, not by vendor name.