The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Strategy11
Strategy11 formidable Forms |
|
CPEs | cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Strategy11
Strategy11 formidable Forms |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser. | |
Title | Formidable Form Builder < 2.05.03 - Unauthenticated Stored Cross-Site Scripting | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:36.437Z
Updated: 2024-10-16T18:03:37.388Z
Reserved: 2024-10-15T17:54:31.373Z
Link: CVE-2017-20192
Vulnrichment
Updated: 2024-10-16T17:40:10.323Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T07:15:05.147
Modified: 2024-10-16T16:38:14.557
Link: CVE-2017-20192
Redhat
No data.