CVE-2017-20194
Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure
Record summary
CVE-2017-20194 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 16, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Formidable Form Builder plugin for WordPressBrowse strategy11 / Formidable Form Builder plugin for WordPress | VulnCheck | Version data not supplied | |
formidable_formsBrowse strategy11 / formidable_formsDefault status: unknown | CVE List | Before 2.05.03 | affected |
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderBrowse strategy11team / Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderDefault status: unaffected | CVE List | Before 2.05.03 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMFormidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureCVSS 5.3
The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Impact
Unauthenticated attackers can export all form entries, leading to potential data breaches and privacy violations.
Remediation
Update to version 2.05.04 or later.
Source: ProjectDiscovery