Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Strategy11

First CVE: Jan 13, 2015Active for: 12 yearsTotal CVEs: 29
38.1
VTI Score
Medium

Strategy11 develops a focused set of WordPress plugins centered on directory listing, classified-ad, and form-building functionality, serving small-business and community websites. The vendor's vulnerability footprint, while concentrated in a narrow product portfolio, skews toward serious outcomes and frequently acquires public exploit code, reflecting the web-facing and user-input-heavy nature of directory and form plugins. The recurring exposure concentrates in products such as Formidable Forms and Business Directory Plugin and clusters persistently around input-handling weaknesses including cross-site scripting, SQL injection, cross-site request forgery, and untrusted deserialization—vulnerability classes endemic to web applications that parse user submissions and render dynamic content. Defenders should prioritize patching this vendor's plugins on internet-exposed WordPress sites, as these weakness classes are routinely weaponized in plugin-focused scanning campaigns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
29
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Strategy11 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2015
11 years ago
Most Recent CVE
Dec 13, 2024
588 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-3254CRITICAL
The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available
Oct 31, 20229.844NOYES
CVE-2023-2877HIGH
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user
Jun 27, 20238.838NONO
CVE-2017-20192MEDIUM
The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions be
Oct 16, 20246.132NOYES
CVE-2021-24884CRITICAL
The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remot
Oct 25, 20219.631NONO
CVE-2019-15780CRITICAL
The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
Aug 29, 20199.831NONO
CVE-2014-10013HIGH
SQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the keywordphrase paramet
Jan 13, 20157.530NOYES
CVE-2017-20194MEDIUM
The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This make
Oct 16, 20245.329NOYES
CVE-2023-24419HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions.
Feb 28, 20238.827NONO
CVE-2021-24179HIGH
The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11 suffered from a Cross-Site Request Forgery issue, allowing an attacker to make a
May 6, 20218.826NONO
CVE-2023-41801HIGH
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions.
Oct 6, 20238.825NONO
View all 29 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products29 CVEs
55%
31%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network27 (93.1%)
Unknown2 (6.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (93.1%)
High0 (0.0%)
Unknown2 (6.9%)
User Interaction
None10 (34.5%)
Unknown2 (6.9%)
Required17 (58.6%)
Privileges Required
Low5 (17.2%)
High4 (13.8%)
None18 (62.1%)
Unknown2 (6.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (29 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
10.3% of CVEs· 96th percentile
ExploitDB
1 CVE
3.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Strategy11.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Strategy11 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Strategy11's Products

View all 4 CNAs →

Top CWEs