Record summary

CVE-2017-20194 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Formidable Form Builder plugin for WordPress

Browse strategy11 / Formidable Form Builder plugin for WordPress
VulnCheckVersion data not supplied

Default status: unknown

CVE ListBefore 2.05.03affected

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder

Browse strategy11team / Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder

Default status: unaffected

CVE ListBefore 2.05.03affected

Nuclei templates

1
ProjectDiscoveryMEDIUMFormidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureCVSS 5.3

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Impact

Unauthenticated attackers can export all form entries, leading to potential data breaches and privacy violations.

Remediation

Update to version 2.05.04 or later.

WeaknessesCWE-200
AuthorsDhiyaneshDK
Template tagscvecve2017wpscanwordpresswpwp-pluginformidablepassivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:strategy11:formidable_form_builder:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3