CVE-2017-20192

HIGH EXPLOITED NUCLEI LAB

Formidable Form Builder <2.05.03 - XSS

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2017-20192 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including flame-11. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a working proof-of-concept for CVE-2017-20192, a stored XSS vulnerability in Formidable Forms (WordPress) versions before 2.05.03. The PoC includes a Docker lab environment and a script that demonstrates the vulnerability by submitting a crafted entry unauthenticated and verifying the XSS payload execution in the admin entry view.

Description

The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Exploits (1)

nomisec WORKING POC
by flame-11 · client-side
https://github.com/flame-11/CVE-2017-20192-formidable-forms

This repository contains a working proof-of-concept for CVE-2017-20192, a stored XSS vulnerability in Formidable Forms (WordPress) versions before 2.05.03. The PoC includes a Docker lab environment and a script that demonstrates the vulnerability by submitting a crafted entry unauthenticated and verifying the XSS payload execution in the admin entry view.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Formidable Forms (WordPress) < 2.05.03
No auth needed
Prerequisites: Docker environment · WordPress with Formidable Forms plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Formidable Forms < 2.05.02 - Cross-Site Scripting
MEDIUMVERIFIEDby 0xanis
FOFA: body="formidable" && body="wp-content/plugins"

Scores

CVSS v3 8.3
EPSS 0.0100
EPSS Percentile 58.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:5.2.3-php7.3-apache
docker pull wordpress:cli-php7.3

Details

VulnCheck KEV 2024-10-15
CWE
CWE-79
Status published
Products (2)
strategy11/formidable_form_builder < 2.05.03
strategy11team/Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder < 2.05.03
Published Oct 16, 2024
Tracked Since Feb 18, 2026