Formidable Form Builder <2.05.03 - XSS
Title source: llmExploitation Summary
CVE-2017-20192 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including flame-11. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a working proof-of-concept for CVE-2017-20192, a stored XSS vulnerability in Formidable Forms (WordPress) versions before 2.05.03. The PoC includes a Docker lab environment and a script that demonstrates the vulnerability by submitting a crafted entry unauthenticated and verifying the XSS payload execution in the admin entry view.
Description
The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Exploits (1)
This repository contains a working proof-of-concept for CVE-2017-20192, a stored XSS vulnerability in Formidable Forms (WordPress) versions before 2.05.03. The PoC includes a Docker lab environment and a script that demonstrates the vulnerability by submitting a crafted entry unauthenticated and verifying the XSS payload execution in the admin entry view.
Nuclei Templates (1)
body="formidable" && body="wp-content/plugins"
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L