High severity8.3NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2017-20192
CVE-2017-20192
Description
The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:strategy11:formidable_form_builder:*:*:*:*:*:wordpress:*:*Range: <2.05.03
<2.05.03+ 1 more
- (no CPE)range: <2.05.03
- (no CPE)
- strategy11team/Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builderv5Range: 0
Patches
Vulnerability mechanics
References
3- klikki.fi/adv/formidable.htmlnvdExploitThird Party Advisory
- www.wordfence.com/threat-intel/vulnerabilities/id/900fcaab-2424-4ae8-af18-95659db0dbe3nvdThird Party Advisory
- wordpress.org/plugins/formidable/nvdProduct
News mentions
0No linked articles in our index yet.