CVE-2017-20194: Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure
The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frmformspreview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-20194?
CVE-2017-20194 is classified as a high severity vulnerability due to its potential for sensitive data exposure.
How do I fix CVE-2017-20194?
To fix CVE-2017-20194, upgrade the Formidable Form Builder plugin to version 2.05.04 or higher.
Who is affected by CVE-2017-20194?
CVE-2017-20194 affects all users of the Formidable Form Builder plugin for WordPress versions up to 2.05.03.
What kind of data is exposed by CVE-2017-20194?
CVE-2017-20194 allows unauthenticated attackers to access and export all form entries from vulnerable forms.
Which WordPress plugin is vulnerable in CVE-2017-20194?
CVE-2017-20194 affects the Formidable Form Builder plugin for WordPress.