Formidable Form Builder < 2.05.03 - Unauthenticated Information Disclosure
2017-11-12 00:00
Jouko PynnöneStrategic Overview
StatusPatched in 2.05.03
Affected PluginFormidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More
Affected Version
< 2.05.03CVSS5.3Medium
CVE
CVE-2017-20194Vulnerability Overview
The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.
Technical Analysis
REMEDIATION: Update to version 2.05.03, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C