Unauthenticated Attackers Can Export All Form Entries via Plugin Flaw
CVE-2017-20194

5.3MEDIUM

Key Information:

Vendor
Strategy11team
Status
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
Vendor
CVE Published:
16 October 2024

Summary

The Formidable Form Builder plugin for WordPress has a vulnerability that allows for sensitive data exposure through the frm_forms_preview AJAX action. This flaw enables unseen attackers to export all entries submitted via form interfaces, posing a significant risk of data leakage. Affected versions of this plugin, up to and including 2.05.03, require immediate attention to safeguard against unauthorized data access. Site administrators must perform updates and implement security measures to mitigate exposure risks.

Affected Version(s)

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder * < 2.05.03

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jouko Pynnöne
.