S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 14, 2025

CVE-2017-20194 Scanner

CVE-2017-20194 Scanner - Information Disclosure vulnerability in Formidable Form Builder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-20194
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.05.03 via the frm_forms_preview AJAX action. This makes it possible for unauthenticated attackers to export all of the form entries for a given form.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builderby strategy11team
AFFECTED< 2.05.03SAFE ✓≥ 2.05.03
formidable_formsby strategy11
AFFECTED< 2.05.03SAFE ✓≥ 2.05.03
Updated Aug 22, 2026View on NVD →
Detail

The Formidable Form Builder plugin is a widely used WordPress plugin designed to help users build comprehensive forms for a range of applications, from contact forms to sophisticated surveys. Developed by Strategy11, this plugin enables individuals and businesses to customize their form-building experience significantly. Many organizations, bloggers, and small businesses use Formidable Form Builder to capture data from their website visitors effectively. It's particularly popular due to its ease of use, flexibility, and the vast array of tools available to non-technical users. With wide usage across diverse WordPress setups, it plays an essential role in data collection for many sites, making its security crucial.

The vulnerability found in the Formidable Form Builder plugin allows Information Disclosure via the frm_forms_preview AJAX action. This vulnerability affects all versions up to and including 2.05.03. Unauthenticated attackers can exploit this by exporting all form entries from a targeted form, breaching data privacy. This exposure of sensitive data can lead to unauthorized access to potentially private information submitted through the affected forms. Ensuring the security of information that passes through the Formidable Form Builder is therefore critical.

Technically, the vulnerability is due to the plugin's improper handling of AJAX requests, specifically through the frm_forms_preview action, which doesn't require authentication. Attackers can send requests to the vulnerable endpoint and retrieve form data without needing valid user credentials. The vulnerable parameter lies within the AJAX function call, where exploiting this issue requires crafting a specific request to export form entries. Such unsecured access points allow for extraction of potentially sensitive user input data submitted through the forms.

If exploited, this vulnerability can lead to significant impacts such as data breaches or privacy violations. Unauthorized attackers accessing form entries can misuse the harvested data for malicious purposes. These might include identity theft, unauthorized disclosures, or selling of private information on the black market. The exposure may also damage the reputation of the website's owner and erode customer trust, especially if it involves sensitive personal or financial data.

REFERENCES

Solution Advice
  • Update the Formidable Form Builder plugin to version 2.05.04 or later to patch the vulnerability.
  • Regularly review and audit the WordPress plugin configurations to ensure security.
  • Implement security measures such as firewalls and intrusion detection systems to prevent unauthorized access attempts.
  • Restrict access to sensitive functions and endpoints in WordPress to authenticated users only.
  • Maintain frequent backups of website data to restore in case of data exposure or loss.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-20194 Scanner - Information Disclosure vulnerability in Formidable Form Builder | S4E