The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Metrics
Affected Vendors & Products
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 30 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strategy11 formidable Form Builder
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:strategy11:formidable_form_builder:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Strategy11 formidable Form Builder
|
Wed, 16 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strategy11
Strategy11 formidable Forms |
|
| CPEs | cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Strategy11
Strategy11 formidable Forms |
|
| Metrics |
ssvc
|
Wed, 16 Oct 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form. | |
| Title | Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T07:31:52.606Z
Updated: 2024-10-16T17:26:14.837Z
Reserved: 2024-10-15T18:53:12.729Z
Link: CVE-2017-20194
Updated: 2024-10-16T17:12:23.186Z
Status : Analyzed
Published: 2024-10-16T08:15:03.453
Modified: 2024-10-30T21:00:25.973
Link: CVE-2017-20194
No data.