Unauthenticated Attackers Can Export All Form Entries via Plugin Flaw
CVE-2017-20194
Key Information:
- Vendor
Wordpress
- Status
- Vendor
- CVE Published:
- 16 October 2024
What is CVE-2017-20194?
The Formidable Form Builder plugin for WordPress has a vulnerability that allows for sensitive data exposure through the frm_forms_preview AJAX action. This flaw enables unseen attackers to export all entries submitted via form interfaces, posing a significant risk of data leakage. Affected versions of this plugin, up to and including 2.05.03, require immediate attention to safeguard against unauthorized data access. Site administrators must perform updates and implement security measures to mitigate exposure risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder * < 2.05.03
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved