The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Strategy11 formidable Form Builder
|
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:strategy11:formidable_form_builder:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Strategy11 formidable Form Builder
|
Wed, 16 Oct 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Strategy11
Strategy11 formidable Forms |
|
CPEs | cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Strategy11
Strategy11 formidable Forms |
|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form. | |
Title | Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T07:31:52.606Z
Updated: 2024-10-16T17:26:14.837Z
Reserved: 2024-10-15T18:53:12.729Z
Link: CVE-2017-20194
Vulnrichment
Updated: 2024-10-16T17:12:23.186Z
NVD
Status : Analyzed
Published: 2024-10-16T08:15:03.453
Modified: 2024-10-30T21:00:25.973
Link: CVE-2017-20194
Redhat
No data.